<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Analysis and Removal</title>
	<atom:link href="http://greatis.com/blog/feed" rel="self" type="application/rss+xml" />
	<link>http://greatis.com/blog</link>
	<description>Malware Analysis and Removal</description>
	<lastBuildDate>Fri, 25 May 2012 03:34:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>OMEGLEVIDSCHECK.EXE is Trojan Agent</title>
		<link>http://greatis.com/blog/how-to-remove-malware/omeglevidscheck-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/omeglevidscheck-exe.htm#comments</comments>
		<pubDate>Fri, 25 May 2012 03:34:15 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Agent.1193472.O]]></category>
		<category><![CDATA[OMEGLEVIDSCHECK.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/omeglevidscheck-exe.htm</guid>
		<description><![CDATA[Is the file OMEGLEVIDSCHECK.EXE located on your computer? Then your computer is infected. We do suggest you should remove OMEGLEVIDSCHECK.EXE from your computer as soon as possible. OMEGLEVIDSCHECK.EXE is Trojan/Backdoor. Kill the process OMEGLEVIDSCHECK.EXE and remove OMEGLEVIDSCHECK.EXE from the Windows startup. Malware Analysis of OMEGLEVIDSCHECK.EXE Full path on a computer: %Appdata%\OmegleVidsCheck.exe Detected by UnHackMe: Item [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Is the file <b>OMEGLEVIDSCHECK.EXE</b> located on your computer? Then your computer is infected.<br />
We do suggest you should remove <b>OMEGLEVIDSCHECK.EXE</b> from your computer as soon as possible.<br />
<b>OMEGLEVIDSCHECK.EXE</b> is Trojan/Backdoor.<br />
Kill the process <b>OMEGLEVIDSCHECK.EXE</b> and remove <b>OMEGLEVIDSCHECK.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of OMEGLEVIDSCHECK.EXE<br />
Full path on a computer: %Appdata%\OmegleVidsCheck.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: OMessenger<br />
Author:<br />
Related File: %APPDATA%\OMEGLEVIDSCHECK.EXE<br />
Type: Registry Run</p>
<p>Item Name: OmegleVidsCheck.exe<br />
Author:<br />
Related File: %APPDATA%\OMEGLEVIDSCHECK.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<p>Item Name: vbc.exe<br />
Author: Unknown<br />
Related File: %APPDATA%\VBC.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>OMEGLEVIDSCHECK.EXE</strong>  is known as:</h3>
<p>Trojan.Agent.1193472.O, a variant of MSIL.Injector.ACA, Trojan.MSIL.Crypt.qhp, Trojan.MulDrop3.50658, Trojan.MSIL.dyg, Backdoor.Fynloski.A, W32.Crypt.QHP.tr</p>
<h3><strong>OMEGLEVIDSCHECK.EXE</strong> hash:</h3>
<ul>
<li>MD5: dd82652dc041b93a9763f6d94b4e2c8c
</div>
<div id="clist">
How to quickly detect <strong>OMEGLEVIDSCHECK.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OMessenger: &#8220;%Appdata%\OmegleVidsCheck.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\dsvgb.txt
<li>%Appdata%\OmegleVidsCheck.exe
<li>%Appdata%\vbc.exe
<li>%Temp%\1C7CF.dmp
<li>%Temp%\A4FA.dmp
<li>%Temp%\dw.log
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/omeglevidscheck-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12821&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/omeglevidscheck-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AFTER.EXE is Trojan Bocinex</title>
		<link>http://greatis.com/blog/how-to-remove-malware/after-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/after-exe.htm#comments</comments>
		<pubDate>Fri, 25 May 2012 03:07:56 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[AFTER.EXE]]></category>
		<category><![CDATA[Bocinex]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/after-exe.htm</guid>
		<description><![CDATA[The file AFTER.EXE is malware related. You must delete the file AFTER.EXE immediately! Delete the file AFTER.EXE without delay! Kill the process AFTER.EXE and remove AFTER.EXE from the Windows startup. Malware Analysis of AFTER.EXE Full path on a computer: %Appdata%\After.exe Detected by UnHackMe: Item Name: bs_stealth Author: Unknown Related File: %APPDATA%\AFTER.EXE Type: Explorer Run Detected [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>AFTER.EXE</b> is malware related.<br />
You must delete the file <b>AFTER.EXE</b> immediately!<br />
Delete the file <b>AFTER.EXE</b> without delay!<br />
Kill the process <b>AFTER.EXE</b> and remove <b>AFTER.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of AFTER.EXE<br />
Full path on a computer: %Appdata%\After.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: bs_stealth<br />
Author: Unknown<br />
Related File: %APPDATA%\AFTER.EXE<br />
Type: Explorer Run</p>
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p>Item Name: bs_stealth<br />
Author: Unknown<br />
Related File: %APPDATA%\AFTER.EXE<br />
Type: Explorer Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 2</h3>
</div>
<div id="blist">
<h3><strong>AFTER.EXE</strong>  is known as:</h3>
<p>Trojan.Bocinex, Trojan.DownLoader6, Mal.Keylog-A</p>
<h3><strong>AFTER.EXE</strong> hash:</h3>
<ul>
<li>MD5: 8025b55b4ebf5dd760b51ebb0e1681fa
</div>
<div id="clist">
How to quickly detect <strong>AFTER.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\run\bs_stealth: &#8220;%Appdata%\After.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\bs_stealth: &#8220;%Appdata%\After.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\After.exe
<li>%Appdata%\bs_log.dat
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/after-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12818&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/after-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LIB32WAOQ.EXE is Trojan MSIL.Prash</title>
		<link>http://greatis.com/blog/how-to-remove-malware/lib32waoq-exe-2.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/lib32waoq-exe-2.htm#comments</comments>
		<pubDate>Fri, 25 May 2012 02:51:24 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[LIB32WAOQ.EXE]]></category>
		<category><![CDATA[MSIL.Prash]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/lib32waoq-exe-2.htm</guid>
		<description><![CDATA[We checked some samples of LIB32WAOQ.EXE and detected the file LIB32WAOQ.EXE as threat. Remove the LIB32WAOQ.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of LIB32WAOQ.EXE Full path on a computer: %SysDir%\lib32waoq.exe Detected by UnHackMe: Item Name: MediaCenter Author: IBM Corporation and others Related File: %SYSDIR%\RGMRTIY.CC3 Type: Svchost DLLs Item Name: sdTQNLxV [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>LIB32WAOQ.EXE</b>  and detected the file <b>LIB32WAOQ.EXE</b> as threat.<br />
Remove the <b>LIB32WAOQ.EXE</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of LIB32WAOQ.EXE<br />
Full path on a computer: %SysDir%\lib32waoq.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: MediaCenter<br />
Author: IBM Corporation and others<br />
Related File: %SYSDIR%\RGMRTIY.CC3<br />
Type: Svchost DLLs</p>
<p>Item Name: sdTQNLxV<br />
Author:<br />
Related File: %SysDir%\Aywtrpm.exe<br />
Type: Auto Services</p>
<p>Item Name: WaoqSvc<br />
Author:<br />
Related File: %WinDir%\System32\lib32waoq.exe<br />
Type: Auto Services</p>
<p>Item Name: gzqrcddiut<br />
Author:<br />
Related File: %SysDir%\TaHoDkS.exe<br />
Type: Auto Services</p>
<p>Item Name: \WINDOWS\Temp\servcie3252A53.exe<br />
Author: Unknown<br />
Related File: %WinDir%\TEMP\SERVCIE3252A53.EXE<br />
Type: Registry Run</p>
<p>Item Name: \WINDOWS\Temp\servcie3252C53.exe<br />
Author: Unknown<br />
Related File: %WinDir%\TEMP\SERVCIE3252C53.EXE<br />
Type: Registry Run</p>
<p>Item Name: \WINDOWS\Temp\servcie3252E53.exe<br />
Author: Unknown<br />
Related File: %WinDir%\TEMP\SERVCIE3252E53.EXE<br />
Type: Registry Run</p>
<p>Item Name: Aywtrpm.exe<br />
Author: Unknown<br />
Related File: %SYSDIR%\AYWTRPM.EXE<br />
Type: Running Processes</p>
<p>Item Name: lib32waoq.exe<br />
Author: Unknown<br />
Related File: %SYSDIR%\LIB32WAOQ.EXE<br />
Type: Running Processes</p>
<p>Item Name: CkRygNF.exe<br />
Author: Unknown<br />
Related File: %SYSDIR%\CKRYGNF.EXE<br />
Type: Running Processes</p>
<p>Item Name: fNubJqX.exe<br />
Author: Unknown<br />
Related File: %SYSDIR%\FNUBJQX.EXE<br />
Type: Running Processes</p>
<p>Item Name: aHpWDlS.exe<br />
Author: Unknown<br />
Related File: %SYSDIR%\AHPWDLS.EXE<br />
Type: Running Processes</p>
<p>Item Name: TaHoDkS.exe<br />
Author: Unknown<br />
Related File: %SYSDIR%\TAHODKS.EXE<br />
Type: Running Processes</p>
<h3>After first reboot detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Tcpz-x86<br />
Author:<br />
Related File: \??\C:\Tcpz-x86.sys<br />
Type: Services detected by Partizan</p>
<p>Item Name: WaoqSvc<br />
Author:<br />
Related File: %WinDir%\System32\lib32waoq.exe<br />
Type: Services detected by Partizan</p>
<h3>Removal Results: Success<br />
Number of reboot: 2</h3>
</div>
<div id="blist">
<h3><strong>LIB32WAOQ.EXE</strong>  is known as:</h3>
<p>Trojan.MSIL.Prash, Trojan.Kazy, Troj.Agent</p>
<h3><strong>LIB32WAOQ.EXE</strong> hash:</h3>
<ul>
<li>MD5: 18582085f5f45ace6940fdda963fdd3d
</div>
<div id="clist">
How to quickly detect <strong>LIB32WAOQ.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_TCPZ-X86\0000\Service: &#8220;Tcpz-x86&#8243;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_TCPZ-X86\0000\DeviceDesc: &#8220;Tcpz-x86&#8243;
<li>HKLM\System\CurrentControlSet\Services\sdTQNLxV\ImagePath: &#8220;%SysDir%\Aywtrpm.exe&#8221;
<li>HKLM\System\CurrentControlSet\Services\Tcpz-x86\ImagePath: &#8220;\??\C:\Tcpz-x86.sys&#8221;
<li>HKLM\System\CurrentControlSet\Services\Tcpz-x86\DisplayName: &#8220;Tcpz-x86&#8243;
<li>HKLM\System\CurrentControlSet\Services\WaoqSvc\ImagePath: &#8220;%WinDir%\System32\lib32waoq.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\Aywtrpm.exe
<li>%SysDir%\fdbzwus.exe
<li>%SysDir%\knpruwy.exe
<li>%SysDir%\lib32waoo.exe
<li>%SysDir%\lib32waoq.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/lib32waoq-exe-2.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12816&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/lib32waoq-exe-2.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MMIOA5QV0P.EXE is Worm Ainslot</title>
		<link>http://greatis.com/blog/worm/mmioa5qv0p-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/mmioa5qv0p-exe.htm#comments</comments>
		<pubDate>Fri, 25 May 2012 02:31:02 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[Ainslot]]></category>
		<category><![CDATA[MMIOA5QV0P.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/mmioa5qv0p-exe.htm</guid>
		<description><![CDATA[The file MMIOA5QV0P.EXE is a computer worm. The worm MMIOA5QV0P.EXE is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the MMIOA5QV0P.EXE problem as soon as possible! Delete the file MMIOA5QV0P.EXE from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>MMIOA5QV0P.EXE</b> is a computer worm.<br />
The worm <b>MMIOA5QV0P.EXE</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>MMIOA5QV0P.EXE</b> problem as soon as possible!<br />
Delete the file <b>MMIOA5QV0P.EXE</b> from all infected computers in your network.<br />
Set up your network firewall against <b>MMIOA5QV0P.EXE</b> intervention.</p>
<h2>Malware Analysis of MMIOA5QV0P.EXE<br />
Full path on a computer: %Appdata%\MMIOA5QV0P.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Windows Defender<br />
Author: Unknown<br />
Related File: %APPDATA%\MMIOA5QV0P.EXE<br />
Type: Explorer Run</p>
<p>Item Name: {F060EBA9-CABC-5AA7-BFEE-B366627F2AA0}<br />
Author: Unknown<br />
Related File: %APPDATA%\MMIOA5QV0P.EXE<br />
Type: ActiveSetup</p>
<p>Item Name: MMIOA5QV0P.exe<br />
Author: Unknown<br />
Related File: %APPDATA%\MMIOA5QV0P.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>MMIOA5QV0P.EXE</strong>  is known as:</h3>
<p>Worm.Ainslot, Worm.AutoRun.cdlp, Trojan.VB, TrojWare.Cosmu.BHL, Trojan.Siggen2</p>
<h3><strong>MMIOA5QV0P.EXE</strong> hash:</h3>
<ul>
<li>MD5: 2b39891133a2653d4c68d4badd864320
</div>
<div id="clist">
How to quickly detect <strong>MMIOA5QV0P.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Active Setup\Installed Components\{F060EBA9-CABC-5AA7-BFEE-B366627F2AA0}\StubPath: &#8220;%Appdata%\MMIOA5QV0P.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\run\Windows Defender: &#8220;%Appdata%\MMIOA5QV0P.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Defender: &#8220;%Appdata%\MMIOA5QV0P.exe&#8221;
<li>HKCU\Software\Microsoft\Active Setup\Installed Components\{F060EBA9-CABC-5AA7-BFEE-B366627F2AA0}\StubPath: &#8220;%Appdata%\MMIOA5QV0P.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Defender: &#8220;%Appdata%\MMIOA5QV0P.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\MMIOA5QV0P.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/mmioa5qv0p-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12814&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/mmioa5qv0p-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MSIZPJ32.DLL is Trojan Downloader6</title>
		<link>http://greatis.com/blog/how-to-remove-malware/msizpj32-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/msizpj32-dll.htm#comments</comments>
		<pubDate>Thu, 24 May 2012 06:37:57 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Downloader6]]></category>
		<category><![CDATA[MSIZPJ32.DLL]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/msizpj32-dll.htm</guid>
		<description><![CDATA[We checked some samples of MSIZPJ32.DLL and detected the file MSIZPJ32.DLL as threat. Remove the MSIZPJ32.DLL file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of MSIZPJ32.DLL Full path on a computer: %SYSDIR%\MSIZPJ32.DLL Detected by UnHackMe: MSIZPJ32.DLL Default location: %SYSDIR%\MSIZPJ32.DLL Removal Results: Success Number of reboot: 1 MSIZPJ32.DLL is known as: Trojan.Downloader6 How [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>MSIZPJ32.DLL</b>  and detected the file <b>MSIZPJ32.DLL</b> as threat.<br />
Remove the <b>MSIZPJ32.DLL</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of MSIZPJ32.DLL<br />
Full path on a computer: %SYSDIR%\MSIZPJ32.DLL</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>MSIZPJ32.DLL</b><br />
Default location: %SYSDIR%\MSIZPJ32.DLL</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>MSIZPJ32.DLL</strong>  is known as:</h3>
<p>Trojan.Downloader6
</p></div>
<div id="clist">
How to quickly detect <strong>MSIZPJ32.DLL</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SYSDIR%\MSIZPJ32.DLL
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/msizpj32-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12812&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/msizpj32-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>50DE5TEEYX.EXE is Trojan Cutwail</title>
		<link>http://greatis.com/blog/how-to-remove-malware/50de5teeyx-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/50de5teeyx-exe.htm#comments</comments>
		<pubDate>Thu, 24 May 2012 06:34:43 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[50DE5TEEYX.EXE]]></category>
		<category><![CDATA[Cutwail]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/50de5teeyx-exe.htm</guid>
		<description><![CDATA[The file 50DE5TEEYX.EXE is malware related. You must delete the file 50DE5TEEYX.EXE immediately! Delete the file 50DE5TEEYX.EXE without delay! Kill the process 50DE5TEEYX.EXE and remove 50DE5TEEYX.EXE from the Windows startup. Malware Analysis of 50DE5TEEYX.EXE Full path on a computer: %UserProfile%\50de5teeyx.exe Detected by UnHackMe: 50DE5TEEYX.EXE Default location: %UserProfile%\50de5teeyx.exe Removal Results: Success Number of reboot: 1 50DE5TEEYX.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>50DE5TEEYX.EXE</b> is malware related.<br />
You must delete the file <b>50DE5TEEYX.EXE</b> immediately!<br />
Delete the file <b>50DE5TEEYX.EXE</b> without delay!<br />
Kill the process <b>50DE5TEEYX.EXE</b> and remove <b>50DE5TEEYX.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of 50DE5TEEYX.EXE<br />
Full path on a computer: %UserProfile%\50de5teeyx.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>50DE5TEEYX.EXE</b><br />
Default location: %UserProfile%\50de5teeyx.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>50DE5TEEYX.EXE</strong>  is known as:</h3>
<p>Trojan.Cutwail, Trojan.Agent</p>
<h3><strong>50DE5TEEYX.EXE</strong> hash:</h3>
<ul>
<li>MD5: 3711a14bd5626d172a291b938e996923
</div>
<div id="clist">
How to quickly detect <strong>50DE5TEEYX.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\50de5teeyx: &#8220;%UserProfile%\50de5teeyx.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%UserProfile%\50de5teeyx.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/50de5teeyx-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12810&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/50de5teeyx-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>KLLKCH4.EXE is Trojan Agent</title>
		<link>http://greatis.com/blog/how-to-remove-malware/kllkch4-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/kllkch4-exe.htm#comments</comments>
		<pubDate>Thu, 24 May 2012 06:29:48 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Agent]]></category>
		<category><![CDATA[KLLKCH4.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/kllkch4-exe.htm</guid>
		<description><![CDATA[Is the file KLLKCH4.EXE located on your computer? Then your computer is infected. We do suggest you should remove KLLKCH4.EXE from your computer as soon as possible. KLLKCH4.EXE is Trojan/Backdoor. Kill the process KLLKCH4.EXE and remove KLLKCH4.EXE from the Windows startup. Malware Analysis of KLLKCH4.EXE Full path on a computer: %Windir%\kllkch4.exe Detected by UnHackMe: KLLKCH4.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Is the file <b>KLLKCH4.EXE</b> located on your computer? Then your computer is infected.<br />
We do suggest you should remove <b>KLLKCH4.EXE</b> from your computer as soon as possible.<br />
<b>KLLKCH4.EXE</b> is Trojan/Backdoor.<br />
Kill the process <b>KLLKCH4.EXE</b> and remove <b>KLLKCH4.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of KLLKCH4.EXE<br />
Full path on a computer: %Windir%\kllkch4.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>KLLKCH4.EXE</b><br />
Default location: %Windir%\kllkch4.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>KLLKCH4.EXE</strong>  is known as:</h3>
<p>Trojan.Agent</p>
<h3><strong>KLLKCH4.EXE</strong> hash:</h3>
<ul>
<li>MD5: d592ad60b4440afc3a92c9d07e887fe4
</div>
<div id="clist">
How to quickly detect <strong>KLLKCH4.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Windir%\kllkch4.exe
<li>%System%\warifout.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/kllkch4-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12808&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/kllkch4-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JL8ZG6FX1U.EXE is Trojan Agent</title>
		<link>http://greatis.com/blog/how-to-remove-malware/jl8zg6fx1u-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/jl8zg6fx1u-exe.htm#comments</comments>
		<pubDate>Thu, 24 May 2012 06:21:22 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Agent]]></category>
		<category><![CDATA[JL8ZG6FX1U.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/jl8zg6fx1u-exe.htm</guid>
		<description><![CDATA[We checked up the file JL8ZG6FX1U.EXE and found it hazardous. The file JL8ZG6FX1U.EXE must be deleted from the system immediately. Kill the process JL8ZG6FX1U.EXE and remove JL8ZG6FX1U.EXE from the Windows startup. Malware Analysis of JL8ZG6FX1U.EXE Full path on a computer: %UserProfile%\jl8zg6fx1u.exe Detected by UnHackMe: JL8ZG6FX1U.EXE Default location: %UserProfile%\jl8zg6fx1u.exe Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>JL8ZG6FX1U.EXE</b> and found it hazardous.<br />
The file <b>JL8ZG6FX1U.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>JL8ZG6FX1U.EXE</b> and remove <b>JL8ZG6FX1U.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of JL8ZG6FX1U.EXE<br />
Full path on a computer: %UserProfile%\jl8zg6fx1u.exe </h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>JL8ZG6FX1U.EXE</b><br />
Default location: %UserProfile%\jl8zg6fx1u.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>JL8ZG6FX1U.EXE</strong>  is known as:</h3>
<p>Trojan.Agent, Trojan.Siggen3</p>
<h3><strong>JL8ZG6FX1U.EXE</strong> hash:</h3>
<ul>
<li>MD5: 85210d6110a5a462481b4c68f1f3c8aa
</div>
<div id="clist">
How to quickly detect <strong>JL8ZG6FX1U.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\jl8zg6fx1u: &#8220;%UserProfile%\jl8zg6fx1u.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%UserProfile%\jl8zg6fx1u.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/jl8zg6fx1u-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12806&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/jl8zg6fx1u-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LIB32WAOQ.EXE is Backdoor Advo</title>
		<link>http://greatis.com/blog/backdoor/lib32waoq-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/lib32waoq-exe.htm#comments</comments>
		<pubDate>Thu, 24 May 2012 06:14:26 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[Advo]]></category>
		<category><![CDATA[LIB32WAOQ.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/lib32waoq-exe.htm</guid>
		<description><![CDATA[The program LIB32WAOQ.EXE is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with LIB32WAOQ.EXE. Download for free: http://www.unhackme.com Malware Analysis of LIB32WAOQ.EXE Full path on a computer: %System%\lib32waoq.exe Detected by UnHackMe: LIB32WAOQ.EXE Default location: %System%\lib32waoq.exe Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>LIB32WAOQ.EXE</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>LIB32WAOQ.EXE</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of LIB32WAOQ.EXE<br />
Full path on a computer: %System%\lib32waoq.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>LIB32WAOQ.EXE</b><br />
Default location: %System%\lib32waoq.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>LIB32WAOQ.EXE</strong>  is known as:</h3>
<p>Backdoor.Advo, TrojanDropper.MSIL, MSIL.Prash</p>
<h3><strong>LIB32WAOQ.EXE</strong> hash:</h3>
<ul>
<li>MD5: 18582085f5f45ace6940fdda963fdd3d
</div>
<div id="clist">
How to quickly detect <strong>LIB32WAOQ.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\SYSTEM\ControlSet001\Services\WaoqSvc\ImagePath: &#8220;%System%\lib32waoq.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%System%\lib32waoq.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/lib32waoq-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12804&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/lib32waoq-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BIN.EXE is Rootkit SpyEye</title>
		<link>http://greatis.com/blog/rootkit/bin-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/rootkit/bin-exe.htm#comments</comments>
		<pubDate>Thu, 24 May 2012 05:59:19 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[BIN.EXE]]></category>
		<category><![CDATA[SpyEye]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/bin-exe.htm</guid>
		<description><![CDATA[Rootkit BIN.EXE is software that enables continued privileged access to a computer while actively hiding its presence. Detection and removal of BIN.EXE may be a very difficult process. You should use anti-rootkit software to fix the BIN.EXE problem. Malware Analysis of BIN.EXE Full path on a computer: %Common Appdata%\default\bin.exe Detected by UnHackMe: Item Name: default [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Rootkit <b>BIN.EXE</b> is software that enables continued privileged access to a computer while actively hiding its presence.<br />
Detection and removal of <b>BIN.EXE</b> may be a very difficult process.<br />
You should  use anti-rootkit software to fix the <b>BIN.EXE</b> problem.</p>
<h2>Malware Analysis of BIN.EXE<br />
Full path on a computer: %Common Appdata%\default\bin.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: default<br />
Author: Unknown<br />
Related File: %COMMON APPDATA%\DEFAULT\BIN.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>BIN.EXE</strong>  is known as:</h3>
<p>Rootkit.SpyEye, Trojan.Hottrend</p>
<h3><strong>BIN.EXE</strong> hash:</h3>
<ul>
<li>MD5: 08ab7f68c6b3a4a2a745cc244d41d213
</div>
<div id="clist">
How to quickly detect <strong>BIN.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\default: &#8220;%Common Appdata%\default\bin.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\Mozilla\Firefox\Profiles\gi17c3pt.default\user.js
<li>%Common Appdata%\default\bin.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/rootkit/bin-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12802&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/rootkit/bin-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>G_SERVER.DLL is Backdoor Hupigon</title>
		<link>http://greatis.com/blog/backdoor/g_server-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/g_server-dll.htm#comments</comments>
		<pubDate>Thu, 24 May 2012 03:24:56 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[G_SERVER.DLL]]></category>
		<category><![CDATA[Hupigon]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/g_server-dll.htm</guid>
		<description><![CDATA[The program G_SERVER.DLL is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with G_SERVER.DLL. Download for free: http://www.unhackme.com Malware Analysis of G_SERVER.DLL Full path on a computer: %WinDir%\G_Server.exe After first reboot detected by UnHackMe: Item Name: PigeonServer Author: Related File: %WinDir%\G_Server.exe Type: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>G_SERVER.DLL</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>G_SERVER.DLL</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of G_SERVER.DLL<br />
Full path on a computer: %WinDir%\G_Server.exe</h2>
<div id="alist">
<h3>After first reboot detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: PigeonServer<br />
Author:<br />
Related File: %WinDir%\G_Server.exe<br />
Type: Auto Services</p>
<p>Item Name: PigeonServer<br />
Author:<br />
Related File: %WinDir%\G_SERVER.EXE<br />
Type: Services detected by Partizan</p>
<p>Item Name: mchInjDrv<br />
Author:<br />
Related File: \??\%WinDir%\TEMP\mc21.tmp<br />
Type: Services detected by Partizan</p>
<h3>After second reboot detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: G_Server.DLL<br />
Author: Unknown<br />
Related File: %WinDir%\G_SERVER.DLL<br />
Type: Detected using Heuristic Algorithm</p>
<p>Item Name: G_ServerKey.DLL<br />
Author: Unknown<br />
Related File: %WinDir%\G_SERVERKEY.DLL<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 3</h3>
</div>
<div id="blist">
<h3><strong>G_SERVER.DLL</strong>  is known as:</h3>
<p>Backdoor.Hupigon, Backdoor.Graybird</p>
<h3><strong>G_SERVER.DLL</strong> hash:</h3>
<ul>
<li>MD5: 70b1ddcd523542c0450ea64a5a241c12
</div>
<div id="clist">
How to quickly detect <strong>G_SERVER.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_MCHINJDRV\0000\Service: &#8220;mchInjDrv&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_MCHINJDRV\0000\DeviceDesc: &#8220;mchInjDrv&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_PIGEONSERVER\0000\Service: &#8220;PigeonServer&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_PIGEONSERVER\0000\DeviceDesc: &#8220;Pigeon_Server&#8221;
<li>HKLM\System\CurrentControlSet\Services\mchInjDrv\ImagePath: &#8220;\??\%WinDir%\TEMP\mc21.tmp&#8221;
<li>HKLM\System\CurrentControlSet\Services\PigeonServer\ImagePath: &#8220;%WinDir%\G_Server.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\G_Server.DLL
<li>%WinDir%\G_Server.exe
<li>%WinDir%\G_ServerKey.DLL
<li>%WinDir%\G_Server_HOOk.DLL
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/g_server-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12800&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/g_server-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AUDIO PERFORMER53484.EXE is Trojan InstallBrain</title>
		<link>http://greatis.com/blog/how-to-remove-malware/audio-performer53484-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/audio-performer53484-exe.htm#comments</comments>
		<pubDate>Wed, 23 May 2012 03:09:45 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[AUDIO PERFORMER53484.EXE]]></category>
		<category><![CDATA[InstallBrain]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/audio-performer53484-exe.htm</guid>
		<description><![CDATA[The file AUDIO PERFORMER53484.EXE is malware related. You must delete the file AUDIO PERFORMER53484.EXE immediately! Delete the file AUDIO PERFORMER53484.EXE without delay! Kill the process AUDIO PERFORMER53484.EXE and remove AUDIO PERFORMER53484.EXE from the Windows startup. Malware Analysis of AUDIO PERFORMER53484.EXE Full path on a computer: %Temp%\Audio Performer53484.exe Detected by UnHackMe: AUDIO PERFORMER53484.EXE Default location: %Temp%\Audio [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>AUDIO PERFORMER53484.EXE</b> is malware related.<br />
You must delete the file <b>AUDIO PERFORMER53484.EXE</b> immediately!<br />
Delete the file <b>AUDIO PERFORMER53484.EXE</b> without delay!<br />
Kill the process <b>AUDIO PERFORMER53484.EXE</b> and remove <b>AUDIO PERFORMER53484.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of AUDIO PERFORMER53484.EXE<br />
Full path on a computer: %Temp%\Audio Performer53484.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>AUDIO PERFORMER53484.EXE</b><br />
Default location: %Temp%\Audio Performer53484.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>AUDIO PERFORMER53484.EXE</strong>  is known as:</h3>
<p>Trojan.InstallBrain, Adware.Downware</p>
<h3><strong>AUDIO PERFORMER53484.EXE</strong> hash:</h3>
<ul>
<li>MD5: 13c5320aa895e481c527a36b53db48da
</div>
<div id="clist">The file tries to connect to the dangerous web site.</div>
<div id="clist">
How to quickly detect <strong>AUDIO PERFORMER53484.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Audio Performer53484.exe: &#8220;&#8221;%Temp%\Audio Performer53484.exe&#8221; /XML=&#8221;%Temp%\1.tmp&#8221; /STP=1:2&#8243;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Temp%\Audio Performer53484.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/audio-performer53484-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12798&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/audio-performer53484-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LINGPC.EXE is Trojan MSIL.KeyLogger</title>
		<link>http://greatis.com/blog/how-to-remove-malware/lingpc-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/lingpc-exe.htm#comments</comments>
		<pubDate>Wed, 23 May 2012 02:55:07 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[LINGPC.EXE]]></category>
		<category><![CDATA[MSIL.KeyLogger)]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/lingpc-exe.htm</guid>
		<description><![CDATA[Is the file LINGPC.EXE located on your computer? Then your computer is infected. We do suggest you should remove LINGPC.EXE from your computer as soon as possible. LINGPC.EXE is Trojan/Backdoor. Kill the process LINGPC.EXE and remove LINGPC.EXE from the Windows startup. Malware Analysis of LINGPC.EXE Full path on a computer: %Appdata%\Microsoft\Windows\Drivers\lingpc.exe Detected by UnHackMe: Item [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Is the file <b>LINGPC.EXE</b> located on your computer? Then your computer is infected.<br />
We do suggest you should remove <b>LINGPC.EXE</b> from your computer as soon as possible.<br />
<b>LINGPC.EXE</b> is Trojan/Backdoor.<br />
Kill the process <b>LINGPC.EXE</b> and remove <b>LINGPC.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of LINGPC.EXE<br />
Full path on a computer: %Appdata%\Microsoft\Windows\Drivers\lingpc.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Adobe Drivers<br />
Author: Windows Photo Viewer<br />
Related File: %APPDATA%\MICROSOFT\WINDOWS\DRIVERS\LINGPC.EXE<br />
Type: Registry Run</p>
<p>Item Name: lingpc.exe<br />
Author: Windows Photo Viewer<br />
Related File: %APPDATA%\MICROSOFT\WINDOWS\DRIVERS\LINGPC.EXE<br />
Type: Running Processes</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>LINGPC.EXE</strong>  is known as:</h3>
<p>Trojan.MSIL.KeyLogger</p>
<h3><strong>LINGPC.EXE</strong> hash:</h3>
<ul>
<li>MD5: f67babe9f92b3b038146c14c497b1870
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>LINGPC.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Adobe Drivers: &#8220;%Appdata%\Microsoft\Windows\Drivers\lingpc.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\Microsoft\Windows\Drivers\lingpc.exe
<li>%Temp%\Software\ttreceipt.exe
<li>%Temp%\Software\ttreceipt.jpg
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/lingpc-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12796&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/lingpc-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NBJICJ98.EXE is Trojan Agent</title>
		<link>http://greatis.com/blog/how-to-remove-malware/nbjicj98-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/nbjicj98-exe.htm#comments</comments>
		<pubDate>Wed, 23 May 2012 02:45:39 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Agent]]></category>
		<category><![CDATA[NBJICJ98.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/nbjicj98-exe.htm</guid>
		<description><![CDATA[The file NBJICJ98.EXE is malware related. You must delete the file NBJICJ98.EXE immediately! Delete the file NBJICJ98.EXE without delay! Kill the process NBJICJ98.EXE and remove NBJICJ98.EXE from the Windows startup. Malware Analysis of NBJICJ98.EXE Full path on a computer: %Appdata%\nbjicj98.exe Detected by UnHackMe: Item Name: nbjicj98 Author: Unknown Related File: %APPDATA%\NBJICJ98.EXE Type: Registry Run Item [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>NBJICJ98.EXE</b> is malware related.<br />
You must delete the file <b>NBJICJ98.EXE</b> immediately!<br />
Delete the file <b>NBJICJ98.EXE</b> without delay!<br />
Kill the process <b>NBJICJ98.EXE</b> and remove <b>NBJICJ98.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of NBJICJ98.EXE<br />
Full path on a computer: %Appdata%\nbjicj98.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: nbjicj98<br />
Author: Unknown<br />
Related File: %APPDATA%\NBJICJ98.EXE<br />
Type: Registry Run</p>
<p>Item Name: nbjicj98.exe<br />
Author: Unknown<br />
Related File: %APPDATA%\NBJICJ98.EXE<br />
Type: Running Processes</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>NBJICJ98.EXE</strong>  is known as:</h3>
<p>Trojan.Agent, Trojan.DownLoad2</p>
<h3><strong>NBJICJ98.EXE</strong> hash:</h3>
<ul>
<li>MD5: 4a7ef491c4db956facd6026427dc2d54
</div>
<div id="clist">The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.</div>
<div id="clist">
How to quickly detect <strong>NBJICJ98.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\nbjicj98: &#8220;%Appdata%\nbjicj98.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\nbjicj98.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/nbjicj98-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12794&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/nbjicj98-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SHIELD.EXE is Trojan CodecPack</title>
		<link>http://greatis.com/blog/how-to-remove-malware/shield-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/shield-exe.htm#comments</comments>
		<pubDate>Wed, 23 May 2012 02:36:29 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[CodecPack]]></category>
		<category><![CDATA[SHIELD.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/shield-exe.htm</guid>
		<description><![CDATA[We checked up the file SHIELD.EXE and found it hazardous. The file SHIELD.EXE must be deleted from the system immediately. Kill the process SHIELD.EXE and remove SHIELD.EXE from the Windows startup. Malware Analysis of SHIELD.EXE Full path on a computer: %SysDir%\Shield.exe Detected by UnHackMe: SHIELD.EXE Default location: %SysDir%\Shield.exe Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>SHIELD.EXE</b> and found it hazardous.<br />
The file <b>SHIELD.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>SHIELD.EXE</b> and remove <b>SHIELD.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of SHIELD.EXE<br />
Full path on a computer: %SysDir%\Shield.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>SHIELD.EXE</b><br />
Default location: %SysDir%\Shield.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>SHIELD.EXE</strong>  is known as:</h3>
<p>Trojan.CodecPack, Trojan.Scar, Trojan.Jorik</p>
<h3><strong>SHIELD.EXE</strong> hash:</h3>
<ul>
<li>MD5: a45a1ccf6842b032b7f2ef2f2255c81c
</div>
<div id="clist">
How to quickly detect <strong>SHIELD.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Shield.exe: &#8220;%SysDir%\Shield.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\Shield.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/shield-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12792&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/shield-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE</title>
		<link>http://greatis.com/blog/unknown/winrar-password-unlocker-2012-1-8v-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/unknown/winrar-password-unlocker-2012-1-8v-exe.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 10:40:30 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[unknown]]></category>
		<category><![CDATA[WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/winrar-password-unlocker-2012-1-8v-exe.htm</guid>
		<description><![CDATA[WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE is unknown, probably legitimate. If the file WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE is located on your computer, download UnHackMe for free to fix the problem with WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE. Malware Analysis of WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE Full path on a computer: %TEMP%\WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE Detected [...]]]></description>
			<content:encoded><![CDATA[<p class="sign"><b>WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE</b> is unknown, probably legitimate.<br />
If the file <b>WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE</b> is located on your computer, download <a href="http://www.greatis.com/unhackme/download.htm">UnHackMe for free</a> to fix the problem with <b>WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE</b>.</p>
<h2>Malware Analysis of WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE<br />
Full path on a computer: %TEMP%\WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE</b><br />
Default location: %TEMP%\WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="clist">
How to quickly detect <strong>WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\WINRAR PASSWORD UNLOCKER 2012 1.8V.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/unknown/winrar-password-unlocker-2012-1-8v-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12790&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/unknown/winrar-password-unlocker-2012-1-8v-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DISPLAYOSD.EXE is Trojan Downloader5</title>
		<link>http://greatis.com/blog/how-to-remove-malware/displayosd-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/displayosd-exe.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 10:00:11 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[DISPLAYOSD.EXE]]></category>
		<category><![CDATA[DownLoader5]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/displayosd-exe.htm</guid>
		<description><![CDATA[The file DISPLAYOSD.EXE is malware related. You must delete the file DISPLAYOSD.EXE immediately! Delete the file DISPLAYOSD.EXE without delay! Kill the process DISPLAYOSD.EXE and remove DISPLAYOSD.EXE from the Windows startup. Malware Analysis of DISPLAYOSD.EXE Full path on a computer: %APPDATA%\MICROSOFT\WINDOWS\DISPLAYOSD.EXE Detected by UnHackMe: DISPLAYOSD.EXE Default location: %APPDATA%\MICROSOFT\WINDOWS\DISPLAYOSD.EXE Removal Results: Success Number of reboot: 1 DISPLAYOSD.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>DISPLAYOSD.EXE</b> is malware related.<br />
You must delete the file <b>DISPLAYOSD.EXE</b> immediately!<br />
Delete the file <b>DISPLAYOSD.EXE</b> without delay!<br />
Kill the process <b>DISPLAYOSD.EXE</b> and remove <b>DISPLAYOSD.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of DISPLAYOSD.EXE<br />
Full path on a computer: %APPDATA%\MICROSOFT\WINDOWS\DISPLAYOSD.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>DISPLAYOSD.EXE</b><br />
Default location: %APPDATA%\MICROSOFT\WINDOWS\DISPLAYOSD.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>DISPLAYOSD.EXE</strong>  is known as:</h3>
<p>Trojan.Downloader5
</p></div>
<div id="clist">
How to quickly detect <strong>DISPLAYOSD.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%APPDATA%\MICROSOFT\WINDOWS\DISPLAYOSD.EXE
<li>%PROFILE%\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\U98D4X8H\UPDATE1016[1].DAT
<li>%APPDATA%\MICROSOFT\WINDOWS\PREFERENCES
<li>%PROFILE%\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\KHMHGZ4F\UPDATE1015[1].DAT
<li>%APPDATA%\MICROSOFT\WINDOWS\SETUP.DAT
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/displayosd-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12788&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/displayosd-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GOOGLEUP.EXE is Worm Prolaco</title>
		<link>http://greatis.com/blog/worm/googleup-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/googleup-exe.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 09:55:58 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[GOOGLEUP.EXE]]></category>
		<category><![CDATA[Prolaco]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/googleup-exe.htm</guid>
		<description><![CDATA[Is the file GOOGLEUP.EXE located on your computer? Then your computer is infected. We do suggest you should remove GOOGLEUP.EXE from your computer as soon as possible. GOOGLEUP.EXE is Trojan/Backdoor. Kill the process GOOGLEUP.EXE and remove GOOGLEUP.EXE from the Windows startup. Malware Analysis of GOOGLEUP.EXE Full path on a computer: %System%\Googleup.exe Detected by UnHackMe: GOOGLEUP.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Is the file <b>GOOGLEUP.EXE</b> located on your computer? Then your computer is infected.<br />
We do suggest you should remove <b>GOOGLEUP.EXE</b> from your computer as soon as possible.<br />
<b>GOOGLEUP.EXE</b> is Trojan/Backdoor.<br />
Kill the process <b>GOOGLEUP.EXE</b> and remove <b>GOOGLEUP.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of GOOGLEUP.EXE<br />
Full path on a computer: %System%\Googleup.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>GOOGLEUP.EXE</b><br />
Default location: %System%\Googleup.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>GOOGLEUP.EXE</strong>  is known as:</h3>
<p>Worm.Prolaco</p>
<h3><strong>GOOGLEUP.EXE</strong> hash:</h3>
<ul>
<li>MD5: 4d6501531228079afef5b87dd04af31a
</div>
<div id="clist">
How to quickly detect <strong>GOOGLEUP.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\GoogleUpdaterv1: &#8220;%System%\Googleup.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Windir%\mswinsck.sys
<li>%System%\explore.exe
<li>%System%\Googleup.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/googleup-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12786&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/googleup-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SVCXDCL32.EXE is Troyan Barys</title>
		<link>http://greatis.com/blog/troyan-2/svcxdcl32-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/troyan-2/svcxdcl32-exe.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 09:49:11 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Troyan]>]]></category>
		<category><![CDATA[Barys]]></category>
		<category><![CDATA[SVCXDCL32.EXE]]></category>
		<category><![CDATA[Troyan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/svcxdcl32-exe.htm</guid>
		<description><![CDATA[We checked up the file SVCXDCL32.EXE and found it hazardous. The file SVCXDCL32.EXE must be deleted from the system immediately. Kill the process SVCXDCL32.EXE and remove SVCXDCL32.EXE from the Windows startup. Malware Analysis of SVCXDCL32.EXE Full path on a computer: %AppData%\svcxdcl32.exe Detected by UnHackMe: SVCXDCL32.EXE Default location: %AppData%\svcxdcl32.exe Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>SVCXDCL32.EXE</b> and found it hazardous.<br />
The file <b>SVCXDCL32.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>SVCXDCL32.EXE</b> and remove <b>SVCXDCL32.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of SVCXDCL32.EXE<br />
Full path on a computer: %AppData%\svcxdcl32.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>SVCXDCL32.EXE</b><br />
Default location: %AppData%\svcxdcl32.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>SVCXDCL32.EXE</strong>  is known as:</h3>
<p>Troyan.Barys</p>
<h3><strong>SVCXDCL32.EXE</strong> hash:</h3>
<ul>
<li>MD5: 8a0ddd3b425c49d201473ce3069353d6
</div>
<div id="clist">
How to quickly detect <strong>SVCXDCL32.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Svc2dll: &#8220;%AppData%\svcxdcl32.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%AppData%\svcxdcl32.dat
<li>%AppData%\svcxdcl32.exe
<li>%AppData%\svcxdcl32_v.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/troyan-2/svcxdcl32-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12784&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/troyan-2/svcxdcl32-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BITCOIN.EXE is Backdoor Qbot</title>
		<link>http://greatis.com/blog/backdoor/bitcoin-exe-2.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/bitcoin-exe-2.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 09:23:20 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[BITCOIN.EXE]]></category>
		<category><![CDATA[Qbot]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/bitcoin-exe-2.htm</guid>
		<description><![CDATA[The program BITCOIN.EXE is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with BITCOIN.EXE. Download for free: http://www.unhackme.com Malware Analysis of BITCOIN.EXE Full path on a computer: %Temp%\tmp878dd1ff\bitcoin.exe Detected by UnHackMe: BITCOIN.EXE Default location: %Temp%\tmp878dd1ff\bitcoin.exe Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>BITCOIN.EXE</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>BITCOIN.EXE</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of BITCOIN.EXE<br />
Full path on a computer: %Temp%\tmp878dd1ff\bitcoin.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>BITCOIN.EXE</b><br />
Default location: %Temp%\tmp878dd1ff\bitcoin.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>BITCOIN.EXE</strong>  is known as:</h3>
<p>Backdoor.Qbot</p>
<h3><strong>BITCOIN.EXE</strong> hash:</h3>
<ul>
<li>MD5: 1bbb6ef0487c8100eb7acddfcb12fde8
</div>
<div id="clist">
How to quickly detect <strong>BITCOIN.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%AppData%\SCleaner\config
<li>%AppData%\SCleaner\scleaner.exe
<li>%AppData%\SCleaner\sndmgr.exe
<li>%Temp%\tmp878dd1ff\bitcoin.exe
<li>%AppData%\Segoep\uqyr.exi
<li>%AppData%\Upilve\evis.exe
<li>%Temp%\tmp90b9d3dc.bat
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/bitcoin-exe-2.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12782&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/bitcoin-exe-2.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>QGL6WO88SW.EXE is Trojan Cutwail</title>
		<link>http://greatis.com/blog/how-to-remove-malware/qgl6wo88sw-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/qgl6wo88sw-exe.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 09:16:23 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Cutwail]]></category>
		<category><![CDATA[QGL6WO88SW.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/qgl6wo88sw-exe.htm</guid>
		<description><![CDATA[The file QGL6WO88SW.EXE is malware related. You must delete the file QGL6WO88SW.EXE immediately! Delete the file QGL6WO88SW.EXE without delay! Kill the process QGL6WO88SW.EXE and remove QGL6WO88SW.EXE from the Windows startup. Malware Analysis of QGL6WO88SW.EXE Full path on a computer: %UserProfile%\qgl6wo88sw.exe Detected by UnHackMe: QGL6WO88SW.EXE Default location: %UserProfile%\qgl6wo88sw.exe Removal Results: Success Number of reboot: 1 QGL6WO88SW.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>QGL6WO88SW.EXE</b> is malware related.<br />
You must delete the file <b>QGL6WO88SW.EXE</b> immediately!<br />
Delete the file <b>QGL6WO88SW.EXE</b> without delay!<br />
Kill the process <b>QGL6WO88SW.EXE</b> and remove <b>QGL6WO88SW.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of QGL6WO88SW.EXE<br />
Full path on a computer: %UserProfile%\qgl6wo88sw.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>QGL6WO88SW.EXE</b><br />
Default location: %UserProfile%\qgl6wo88sw.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>QGL6WO88SW.EXE</strong>  is known as:</h3>
<p>Trojan.Cutwail</p>
<h3><strong>QGL6WO88SW.EXE</strong> hash:</h3>
<ul>
<li>MD5: 17c9efaf7f70581319b1cf2a3e66d20c
</div>
<div id="clist">
How to quickly detect <strong>QGL6WO88SW.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\qgl6wo88sw: &#8220;%UserProfile%\qgl6wo88sw.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%UserProfile%\qgl6wo88sw.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/qgl6wo88sw-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12780&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/qgl6wo88sw-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WWMY7SHQ7D.EXE is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/wwmy7shq7d-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/wwmy7shq7d-exe.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 07:39:43 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[WWMY7SHQ7D.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/wwmy7shq7d-exe.htm</guid>
		<description><![CDATA[We checked some samples of WWMY7SHQ7D.EXE and detected the file WWMY7SHQ7D.EXE as threat. Remove the WWMY7SHQ7D.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of WWMY7SHQ7D.EXE Full path on a computer: %UserProfile%\wwmy7shq7d.exe Detected by UnHackMe: WWMY7SHQ7D.EXE Default location: %UserProfile%\wwmy7shq7d.exe Removal Results: Success Number of reboot: 1 WWMY7SHQ7D.EXE is known as: Trojan.Downloader WWMY7SHQ7D.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>WWMY7SHQ7D.EXE</b>  and detected the file <b>WWMY7SHQ7D.EXE</b> as threat.<br />
Remove the <b>WWMY7SHQ7D.EXE</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of WWMY7SHQ7D.EXE<br />
Full path on a computer: %UserProfile%\wwmy7shq7d.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>WWMY7SHQ7D.EXE</b><br />
Default location: %UserProfile%\wwmy7shq7d.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>WWMY7SHQ7D.EXE</strong>  is known as:</h3>
<p>Trojan.Downloader</p>
<h3><strong>WWMY7SHQ7D.EXE</strong> hash:</h3>
<ul>
<li>MD5: 366bbaf55c66966bcff276556a1606ca
</div>
<div id="clist">
How to quickly detect <strong>WWMY7SHQ7D.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\wwmy7shq7d: &#8220;%UserProfile%\wwmy7shq7d.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%UserProfile%\wwmy7shq7d.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/wwmy7shq7d-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12778&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/wwmy7shq7d-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IQS.EXE is Trojan Facebook</title>
		<link>http://greatis.com/blog/how-to-remove-malware/iqs-exe-2.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/iqs-exe-2.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 07:28:26 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[IQS.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/iqs-exe-2.htm</guid>
		<description><![CDATA[The file IQS.EXE is a computer worm. The worm IQS.EXE is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the IQS.EXE problem as soon as possible! Delete the file IQS.EXE from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>IQS.EXE</b> is a computer worm.<br />
The worm <b>IQS.EXE</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>IQS.EXE</b> problem as soon as possible!<br />
Delete the file <b>IQS.EXE</b> from all infected computers in your network.<br />
Set up your network firewall against <b>IQS.EXE</b> intervention.</p>
<h2>Malware Analysis of IQS.EXE<br />
Full path on a computer: %WinDir%\iqs.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Microsoft Firevall Engine<br />
Author: Google Inc.<br />
Related File: %WinDir%\IQS.EXE<br />
Type: Registry Run</p>
<p>Item Name: iqs.exe<br />
Author: Google Inc.<br />
Related File: %WinDir%\IQS.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>IQS.EXE</strong>  is known as:</h3>
<p>Trojan.Facebook, Trojan.Gyimface, Trojan.Msil, Worm.Stekct</p>
<h3><strong>IQS.EXE</strong> hash:</h3>
<ul>
<li>MD5: 7a25f877bdab40a055cf8452885d1952
</div>
<div id="clist">
How to quickly detect <strong>IQS.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Firevall Engine: &#8220;c:\windows\iqs.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Firevall Engine: &#8220;c:\windows\iqs.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\iqs.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/iqs-exe-2.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12776&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/iqs-exe-2.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VM_STI.EXE is Trojan PWS.QQRob</title>
		<link>http://greatis.com/blog/how-to-remove-malware/vm_sti-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/vm_sti-exe.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 03:44:12 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[PWS.QQRob]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[VM_STI.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/vm_sti-exe.htm</guid>
		<description><![CDATA[We checked some samples of VM_STI.EXE and detected the file VM_STI.EXE as threat. Remove the VM_STI.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of VM_STI.EXE Full path on a computer: %SysDir%\VM_STI.exe Detected by UnHackMe: VM_STI.EXE Default location: %SYSDIR%\VM_STI.EXE Removal Results: Success Number of reboot: 1 VM_STI.EXE is known as: Trojan.PWS.QQRob, Worm.Mytob, [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>VM_STI.EXE</b>  and detected the file <b>VM_STI.EXE</b> as threat.<br />
Remove the <b>VM_STI.EXE</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of VM_STI.EXE<br />
Full path on a computer: %SysDir%\VM_STI.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>VM_STI.EXE</b><br />
Default location: %SYSDIR%\VM_STI.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>VM_STI.EXE</strong>  is known as:</h3>
<p>Trojan.PWS.QQRob, Worm.Mytob, Trojan.PWS.Qqrobber</p>
<h3><strong>VM_STI.EXE</strong> hash:</h3>
<ul>
<li>MD5: a9cfc6cf103b6335c4abb7b2f1b4ff9c
</div>
<div id="clist">
How to quickly detect <strong>VM_STI.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VM_STI: &#8220;%SysDir%\VM_STI.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\VM_STI.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/vm_sti-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12774&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/vm_sti-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LEXPLORER.EXE is Worm Rebhip</title>
		<link>http://greatis.com/blog/worm/lexplorer-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/lexplorer-exe.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 03:19:03 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[LEXPLORER.EXE]]></category>
		<category><![CDATA[Rebhip]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/lexplorer-exe.htm</guid>
		<description><![CDATA[The file LEXPLORER.EXE is a computer worm. The worm LEXPLORER.EXE is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the LEXPLORER.EXE problem as soon as possible! Delete the file LEXPLORER.EXE from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>LEXPLORER.EXE</b> is a computer worm.<br />
The worm <b>LEXPLORER.EXE</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>LEXPLORER.EXE</b> problem as soon as possible!<br />
Delete the file <b>LEXPLORER.EXE</b> from all infected computers in your network.<br />
Set up your network firewall against <b>LEXPLORER.EXE</b> intervention.</p>
<h2>Malware Analysis of LEXPLORER.EXE<br />
Full path on a computer: C:\dir\install\install\lexplorer.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Policies<br />
Author: Oracle Corporation<br />
Related File: C:\DIR\INSTALL\INSTALL\LEXPLORER.EXE<br />
Type: Explorer Run</p>
<p>Item Name: {04OHYM65-37FP-1FE4-K76U-0KBA85HM3856}<br />
Author:<br />
Related File: C:\DIR\INSTALL\INSTALL\LEXPLORER.EXE<br />
Type: ActiveSetup</p>
<p>Item Name: svchost<br />
Author: Oracle Corporation<br />
Related File: C:\DIR\INSTALL\INSTALL\LEXPLORER.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>LEXPLORER.EXE</strong>  is known as:</h3>
<p>Worm.Rebhip, Trojan.Rbot, Trojan.Injector, Backdoor.Ursap</p>
<h3><strong>LEXPLORER.EXE</strong> hash:</h3>
<ul>
<li>MD5: 4b9a61da95506308dba4f9dbd1122d07
</div>
<div id="clist">
How to quickly detect <strong>LEXPLORER.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Active Setup\Installed Components\{04OHYM65-37FP-1FE4-K76U-0KBA85HM3856}\StubPath: &#8220;C:\dir\install\install\lexplorer.EXE&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Policies: &#8220;C:\dir\install\install\lexplorer.EXE&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\svchost: &#8220;C:\dir\install\install\lexplorer.EXE&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: &#8220;C:\dir\install\install\lexplorer.EXE&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost: &#8220;C:\dir\install\install\lexplorer.EXE&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>C:\dir\install\install
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\logs.dat
<li>%Temp%\UuU.uUu
<li>%Temp%\XxX.xXx
<li>C:\dir\install\install\lexplorer.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/lexplorer-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12772&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/lexplorer-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ITUNES_SERVICE86.EXE is Trojan Ransom.Gimemo</title>
		<link>http://greatis.com/blog/how-to-remove-malware/itunes_service86-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/itunes_service86-exe.htm#comments</comments>
		<pubDate>Tue, 22 May 2012 02:58:28 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[ITUNES_SERVICE86.EXE]]></category>
		<category><![CDATA[Ransom.Gimemo]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/itunes_service86-exe.htm</guid>
		<description><![CDATA[Ransom Screen Locker ITUNES_SERVICE86.EXE is a malicious program. ITUNES_SERVICE86.EXE blocks user access to a computer that it infects. ITUNES_SERVICE86.EXE demands a ransom paid for unlocking the computer. Malware Analysis of ITUNES_SERVICE86.EXE Full path on a computer: %Appdata%\itunes_service86.exe Detected by RegRun Warrior: Item Name: shell Author: Unknown Related File: %Appdata%\itunes_service86.exe Type: System.ini Item Name: UserInit Author: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Ransom Screen Locker <strong>ITUNES_SERVICE86.EXE</strong> is a malicious program. <strong>ITUNES_SERVICE86.EXE</strong> blocks user access to a computer that it infects.  <strong>ITUNES_SERVICE86.EXE</strong> demands a ransom paid for unlocking the computer.</p>
<h2>Malware Analysis of ITUNES_SERVICE86.EXE<br />
Full path on a computer: %Appdata%\itunes_service86.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p>Item Name: shell<br />
Author: Unknown<br />
Related File: %Appdata%\itunes_service86.exe<br />
Type: System.ini</p>
<p>Item Name: UserInit<br />
Author: Unknown<br />
Related File: %Appdata%\itunes_service86.exe,%WinDir%\System32\userinit.exe,<br />
Type: UserInit Value</p>
<p>Item Name: VX5LWxsct4OYCCz<br />
Author: Unknown<br />
Related File: %APPDATA%\ITUNES_SERVICE86.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>ITUNES_SERVICE86.EXE</strong>  is known as:</h3>
<p>Trojan.Ransom.Gimemo, Trojan.Injector, Trojan.LockScreen, Trojan.ABot</p>
<h3><strong>ITUNES_SERVICE86.EXE</strong> hash:</h3>
<ul>
<li>MD5: 7944a9eaac350ae8c8a0d2ddfcc07201
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>ITUNES_SERVICE86.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Active Setup\Installed Components\{XeJngJXf-ODXg-ffJf-IGRj-b8ZmzFObCacv}\VX5LWxsct4OYCCz: &#8220;&#8221;%Appdata%\itunes_service86.exe&#8221; /ActiveX&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VX5LWxsct4OYCCz: &#8220;%Appdata%\itunes_service86.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VX5LWxsct4OYCCz: &#8220;%Appdata%\itunes_service86.exe&#8221;
<li>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: &#8220;%Appdata%\itunes_service86.exe&#8221;
<li>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: &#8220;%Appdata%\itunes_service86.exe,%WinDir%\System32\userinit.exe,&#8221;
<li>HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: &#8220;%Appdata%\itunes_service86.exe&#8221;
<li>HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: &#8220;%Appdata%\itunes_service86.exe,%WinDir%\System32\userinit.exe,&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\itunes_service86.exe</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/itunes_service86-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12770&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/itunes_service86-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Worm Stekct</title>
		<link>http://greatis.com/blog/worm/worm_stekct.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/worm_stekct.htm#comments</comments>
		<pubDate>Mon, 21 May 2012 11:31:32 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[Stekct]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/worm_stekct.htm</guid>
		<description><![CDATA[The &#8220;Worm_Stekct&#8221; is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the &#8220;Worm_Stekct&#8221; problem as soon as possible! Delete the &#8220;Worm_Stekct&#8221; from all infected computers in your network. Set up your network firewall against &#8220;Worm_Stekct&#8221; intervention. Malware Analysis of &#8220;Worm_Stekct&#8221; Full path on [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The <b>&#8220;Worm_Stekct&#8221;</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>&#8220;Worm_Stekct&#8221;</b> problem as soon as possible!<br />
Delete the <b>&#8220;Worm_Stekct&#8221;</b> from all infected computers in your network.<br />
Set up your network firewall against <b>&#8220;Worm_Stekct&#8221;</b> intervention.</p>
<h2>Malware Analysis of &#8220;Worm_Stekct&#8221;<br />
Full path on a computer: %WinDir%\IQS.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Microsoft Firevall Engine<br />
Author: Unknown<br />
Related File: %WinDir%\IQS.EXE<br />
Type: Registry Run</p>
<p>Item Name: IQS.EXE<br />
Author: Unknown<br />
Related File: %WinDir%\IQS.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>&#8220;Worm_Stekct&#8221;</strong>  is known as:</h3>
<p>Worm.Stekct, Worm.Daws, Worm.Multim</p>
<h3><strong>&#8220;Worm_Stekct&#8221;</strong> hash:</h3>
<ul>
<li>MD5: 8fb8586175c88a14efb805c7b427c095
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>&#8220;Worm_Stekct&#8221;</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Firevall Engine: &#8220;c:\windows\IQS.EXE&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Firevall Engine: &#8220;c:\windows\IQS.EXE&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\IQS.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/worm_stekct.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12767&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/worm_stekct.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IQS.EXE is Worm Stekct</title>
		<link>http://greatis.com/blog/worm/iqs-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/iqs-exe.htm#comments</comments>
		<pubDate>Mon, 21 May 2012 11:18:44 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[IQS.EXE]]></category>
		<category><![CDATA[Stekct]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/iqs-exe.htm</guid>
		<description><![CDATA[The file IQS.EXE is a computer worm. The worm IQS.EXE is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the IQS.EXE problem as soon as possible! Delete the file IQS.EXE from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>IQS.EXE</b> is a computer worm.<br />
The worm <b>IQS.EXE</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>IQS.EXE</b> problem as soon as possible!<br />
Delete the file <b>IQS.EXE</b> from all infected computers in your network.<br />
Set up your network firewall against <b>IQS.EXE</b> intervention.</p>
<h2>Malware Analysis of IQS.EXE<br />
Full path on a computer: %WinDir%\IQS.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Microsoft Firevall Engine<br />
Author: Unknown<br />
Related File: %WinDir%\IQS.EXE<br />
Type: Registry Run</p>
<p>Item Name: IQS.EXE<br />
Author: Unknown<br />
Related File: %WinDir%\IQS.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>IQS.EXE</strong>  is known as:</h3>
<p>Worm.Stekct, Worm.Daws, Worm.Multim</p>
<h3><strong>IQS.EXE</strong> hash:</h3>
<ul>
<li>MD5: 8fb8586175c88a14efb805c7b427c095
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>IQS.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Firevall Engine: &#8220;c:\windows\IQS.EXE&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Firevall Engine: &#8220;c:\windows\IQS.EXE&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\IQS.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/iqs-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12761&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/iqs-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Picture13.JPG_www.facebook.com is Worm Stekct</title>
		<link>http://greatis.com/blog/worm/picture13-jpg_www-facebook-com.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/picture13-jpg_www-facebook-com.htm#comments</comments>
		<pubDate>Mon, 21 May 2012 11:10:19 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[Picture13.JPG_www.facebook.com]]></category>
		<category><![CDATA[Stekct]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/iqs-exe.htm</guid>
		<description><![CDATA[The file Picture13.JPG_www.facebook.com is a computer worm. The worm Picture13.JPG_www.facebook.com is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the Picture13.JPG_www.facebook.com problem as soon as possible! Delete the file Picture13.JPG_www.facebook.com from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>Picture13.JPG_www.facebook.com</b> is a computer worm.<br />
The worm <b>Picture13.JPG_www.facebook.com</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>Picture13.JPG_www.facebook.com</b> problem as soon as possible!<br />
Delete the file <b>Picture13.JPG_www.facebook.com</b> from all infected computers in your network.<br />
Set up your network firewall against <b>Picture13.JPG_www.facebook.com</b> intervention.</p>
<h2>Malware Analysis of Picture13.JPG_www.facebook.com<br />
Full path on a computer: %WinDir%\IQS.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Microsoft Firevall Engine<br />
Author: Unknown<br />
Related File: %WinDir%\IQS.EXE<br />
Type: Registry Run</p>
<p>Item Name: IQS.EXE<br />
Author: Unknown<br />
Related File: %WinDir%\IQS.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>Picture13.JPG_www.facebook.com</strong>  is known as:</h3>
<p>Worm.Stekct, Worm.Daws, Worm.Multim</p>
<h3><strong>IQS.EXE</strong> hash:</h3>
<ul>
<li>MD5: 8fb8586175c88a14efb805c7b427c095
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>Picture13.JPG_www.facebook.com</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Firevall Engine: &#8220;c:\windows\IQS.EXE&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Firevall Engine: &#8220;c:\windows\IQS.EXE&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\IQS.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/picture13-jpg_www-facebook-com.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12759&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/picture13-jpg_www-facebook-com.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WINSRV.EXE is Worm Stekct</title>
		<link>http://greatis.com/blog/worm/winsrv-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/winsrv-exe.htm#comments</comments>
		<pubDate>Mon, 21 May 2012 10:56:58 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[Stekct]]></category>
		<category><![CDATA[WINSRV.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/winsrv-exe.htm</guid>
		<description><![CDATA[The file WINSRV.EXE is a computer worm. The worm WINSRV.EXE is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the WINSRV.EXE problem as soon as possible! Delete the file WINSRV.EXE from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>WINSRV.EXE</b> is a computer worm.<br />
The worm <b>WINSRV.EXE</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>WINSRV.EXE</b> problem as soon as possible!<br />
Delete the file <b>WINSRV.EXE</b> from all infected computers in your network.<br />
Set up your network firewall against <b>WINSRV.EXE</b> intervention.</p>
<h2>Malware Analysis of WINSRV.EXE<br />
Full path on a computer: %WinDir%\winsrv.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Microsoft Firevall Engine<br />
Author: Unknown<br />
Related File: %WinDir%\WINSRV.EXE<br />
Type: Registry Run</p>
<p>Item Name: winsrv.exe<br />
Author: Unknown<br />
Related File: %WinDir%\WINSRV.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>WINSRV.EXE</strong>  is known as:</h3>
<p>Worm.Stekct, Worm.Daws, Worm.Multim</p>
<h3><strong>WINSRV.EXE</strong> hash:</h3>
<ul>
<li>MD5: 8fb8586175c88a14efb805c7b427c095
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>WINSRV.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Firevall Engine: &#8220;c:\windows\winsrv.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Firevall Engine: &#8220;c:\windows\winsrv.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\winsrv.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/winsrv-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12749&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/winsrv-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

