<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Analysis and Removal</title>
	<atom:link href="http://greatis.com/blog/feed" rel="self" type="application/rss+xml" />
	<link>http://greatis.com/blog</link>
	<description>Malware Analysis and Removal</description>
	<lastBuildDate>Thu, 09 Feb 2012 12:32:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>STKSCAN.DLL is Trojan Sirefef.BP</title>
		<link>http://greatis.com/blog/how-to-remove-malware/stkscan-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/stkscan-dll.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 12:32:34 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Sirefef.BP]]></category>
		<category><![CDATA[STKSCAN.DLL]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/stkscan-dll.htm</guid>
		<description><![CDATA[Rootkit STKSCAN.DLL is software that enables continued privileged access to a computer while actively hiding its presence. Detection and removal of STKSCAN.DLL may be a very difficult process. You should use anti-rootkit software to fix the STKSCAN.DLL problem. Malware Analysis of STKSCAN.DLL Full path on a computer: %SysDir%\StkScan.dll Detected by RegRun Warrior: STKSCAN.DLL Default location: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Rootkit <b>STKSCAN.DLL</b> is software that enables continued privileged access to a computer while actively hiding its presence.<br />
Detection and removal of <b>STKSCAN.DLL</b> may be a very difficult process.<br />
You should  use anti-rootkit software to fix the <b>STKSCAN.DLL</b> problem.</p>
<h2>Malware Analysis of STKSCAN.DLL<br />
Full path on a computer: %SysDir%\StkScan.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p><b>STKSCAN.DLL</b><br />
Default location: %SysDir%\StkScan.dll</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>STKSCAN.DLL</strong>  is known as:</h3>
<p>Trojan.Sirefef.BP, TR.Sirefef.BP.1, Troj.ZAccess-AB, W32.ZeroAccess.D.tr</p>
<h3><strong>STKSCAN.DLL</strong> hash:</h3>
<ul>
<li>MD5: b89cfbe8cb247b57d8c10adaa66b462b
</div>
<div id="clist">
How to quickly detect <strong>STKSCAN.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_SNP2STD\0000\Service: &#8220;SNP2STD&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_SNP2STD\0000\DeviceDesc: &#8220;Acedrv07&#8243;
<li>HKLM\System\CurrentControlSet\Services\SNP2STD\Parameters\ServiceDll: &#8220;%systemroot%\system32\StkScan.dll&#8221;
<li>HKLM\System\CurrentControlSet\Services\SNP2STD\DisplayName: &#8220;Acedrv07&#8243;
<li>HKLM\System\CurrentControlSet\Services\SNP2STD\Description: &#8220;New service would allow parents to control their children&#8217;s online activity.&#8221;
<li>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: &#8220;%Local Appdata%\3308c706\X&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%WinDir%\$NtUninstallKB3057$
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Local Appdata%\3308c706\@
<li>%Local Appdata%\3308c706\X
<li>%WinDir%\assembly\GAC_MSIL\Desktop.ini
<li>%SysDir%\dds_log_trash.cmd
<li>%SysDir%\StkScan.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/stkscan-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11275&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/stkscan-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>%Local Appdata%\3308c706\X is Rootkit ZeroAccess</title>
		<link>http://greatis.com/blog/rootkit/3308c706-x.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/rootkit/3308c706-x.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 12:29:49 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[X]]></category>
		<category><![CDATA[ZeroAccess]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/3308c706-x.htm</guid>
		<description><![CDATA[Rootkit \3308c706\X is software that enables continued privileged access to a computer while actively hiding its presence. Detection and removal of \3308c706\X may be a very difficult process. You should use anti-rootkit software to fix the \3308c706\X problem. Malware Analysis of X Full path on a computer: %Local Appdata%\3308c706\X Detected by UnHackMe: Item Name: shell [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Rootkit <b>\3308c706\X</b> is software that enables continued privileged access to a computer while actively hiding its presence.<br />
Detection and removal of <b>\3308c706\X</b> may be a very difficult process.<br />
You should  use anti-rootkit software to fix the <b>\3308c706\X</b> problem.
</p>
<h2>Malware Analysis of X<br />
Full path on a computer: %Local Appdata%\3308c706\X</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: shell<br />
Author: Unknown<br />
Related File: %Local Appdata%\3308c706\X<br />
Type: User Shell</p>
<p>Item Name: Rootkit: ZeroAccess 32/64.4<br />
Author: Unknown<br />
Related File:<br />
Type: Devices in Memory</p>
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p>Item Name: shell<br />
Author: Unknown<br />
Related File: %Local Appdata%\3308c706\X<br />
Type: User Shell</p>
<p>Item Name: netbt.sys<br />
Author: Unknown<br />
Related File: %SYSDIR%\DRIVERS\NETBT.SYS<br />
Type: System Drivers Infected by Rootkit</p>
<p>STKSCAN.DLL<br />
Default location: %SYSDIR%\STKSCAN.DLL<br />
MD5: B89CFBE8CB247B57D8C10ADAA66B462B<br />
SHA1: A4023B8E 38F1E18D 0DFFB435 67C5E0AE F6C8086B<br />
File Size: 5 120</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>X</strong>  is known as:</h3>
<p>Rootkit.ZeroAccess, Trojan.Sirefef</p>
<h3><strong>X</strong> hash:</h3>
<ul>
<li>MD5: fde7e556abc385a39b73919e470fbb1d
</div>
<div id="clist">
How to quickly detect <strong>X</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_SNP2STD\0000\Service: &#8220;SNP2STD&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_SNP2STD\0000\DeviceDesc: &#8220;Acedrv07&#8243;
<li>HKLM\System\CurrentControlSet\Services\SNP2STD\Parameters\ServiceDll: &#8220;%systemroot%\system32\StkScan.dll&#8221;
<li>HKLM\System\CurrentControlSet\Services\SNP2STD\DisplayName: &#8220;Acedrv07&#8243;
<li>HKLM\System\CurrentControlSet\Services\SNP2STD\Description: &#8220;New service would allow parents to control their children&#8217;s online activity.&#8221;
<li>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: &#8220;%Local Appdata%\3308c706\X&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%WinDir%\$NtUninstallKB3057$
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Local Appdata%\3308c706\@
<li>%Local Appdata%\3308c706\X
<li>%WinDir%\assembly\GAC_MSIL\Desktop.ini
<li>%SysDir%\dds_log_trash.cmd
<li>%SysDir%\StkScan.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/rootkit/3308c706-x.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11273&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/rootkit/3308c706-x.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCDRNT.DLL is Rootkit ZeroAccess</title>
		<link>http://greatis.com/blog/rootkit/pcdrnt-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/rootkit/pcdrnt-dll.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 12:08:13 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[PCDRNT.DLL]]></category>
		<category><![CDATA[ZeroAccess]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/pcdrnt-dll.htm</guid>
		<description><![CDATA[Rootkit PCDRNT.DLL is software that enables continued privileged access to a computer while actively hiding its presence. Detection and removal of PCDRNT.DLL may be a very difficult process. You should use anti-rootkit software to fix the PCDRNT.DLL problem. Malware Analysis of PCDRNT.DLL Full path on a computer: %SysDir%\PcdrNt.dll Detected by RegRun Warrior: PCDRNT.DLL Default location: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Rootkit <b>PCDRNT.DLL</b> is software that enables continued privileged access to a computer while actively hiding its presence.<br />
Detection and removal of <b>PCDRNT.DLL</b> may be a very difficult process.<br />
You should  use anti-rootkit software to fix the <b>PCDRNT.DLL</b> problem.</p>
<h2>Malware Analysis of PCDRNT.DLL<br />
Full path on a computer: %SysDir%\PcdrNt.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p><b>PCDRNT.DLL</b><br />
Default location: %SysDir%\PcdrNt.dll</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>PCDRNT.DLL</strong>  is known as:</h3>
<p>Rootkit.ZeroAccess, Trojan.Sirefef</p>
<h3><strong>PCDRNT.DLL</strong> hash:</h3>
<ul>
<li>MD5: b89cfbe8cb247b57d8c10adaa66b462b
</div>
<div id="clist">
How to quickly detect <strong>PCDRNT.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_ANTIVIRSCHEDULER\0000\Service: &#8220;antivirscheduler&#8221;
<li>HKLM\System\CurrentControlSet\Services\antivirscheduler\Parameters\ServiceDll: &#8220;%systemroot%\system32\PcdrNt.dll&#8221;
<li>HKLM\System\CurrentControlSet\Services\antivirscheduler\DisplayName: &#8220;Epsonstatusagent2&#8243;
<li>HKLM\System\CurrentControlSet\Services\antivirscheduler\Description: &#8220;New service would allow parents to control their children&#8217;s online activity.&#8221;
<li>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: &#8220;%Local Appdata%\3308c706\X&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%WinDir%\$NtUninstallKB3057$
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Local Appdata%\3308c706\@
<li>%Local Appdata%\3308c706\X
<li>%WinDir%\assembly\GAC_MSIL\Desktop.ini
<li>%SysDir%\dds_log_trash.cmd
<li>%SysDir%\PcdrNt.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/rootkit/pcdrnt-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11271&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/rootkit/pcdrnt-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MAYA70DOCSERVER.DLL is Rootkit ZeroAccess</title>
		<link>http://greatis.com/blog/rootkit/maya70docserver-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/rootkit/maya70docserver-dll.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 11:23:18 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[MAYA70DOCSERVER.DLL]]></category>
		<category><![CDATA[ZeroAccess]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/maya70docserver-dll.htm</guid>
		<description><![CDATA[Rootkit MAYA70DOCSERVER.DLL is software that enables continued privileged access to a computer while actively hiding its presence. Detection and removal of MAYA70DOCSERVER.DLL may be a very difficult process. You should use anti-rootkit software to fix the MAYA70DOCSERVER.DLL problem. Malware Analysis of MAYA70DOCSERVER.DLL Full path on a computer: %SysDir%\maya70docserver.dll Detected by UnHackMe: After first reboot detected [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Rootkit <b>MAYA70DOCSERVER.DLL</b> is software that enables continued privileged access to a computer while actively hiding its presence.<br />
Detection and removal of <b>MAYA70DOCSERVER.DLL</b> may be a very difficult process.<br />
You should  use anti-rootkit software to fix the <b>MAYA70DOCSERVER.DLL</b> problem.</p>
<h2>Malware Analysis of MAYA70DOCSERVER.DLL<br />
Full path on a computer: %SysDir%\maya70docserver.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<h3>After first reboot detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p><b>MAYA70DOCSERVER.DLL</b><br />
Default location:</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>MAYA70DOCSERVER.DLL</strong>  is known as:</h3>
<p>Rootkit.ZeroAccess, Trojan.Sirefef</p>
<h3><strong>MAYA70DOCSERVER.DLL</strong> hash:</h3>
<ul>
<li>MD5: 11028c6a84a967070cb1286550f2058f
</div>
<div id="clist">
How to quickly detect <strong>MAYA70DOCSERVER.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Services\w810mgmt\Parameters\ServiceDll: &#8220;%systemroot%\system32\maya70docserver.dll&#8221;
<li>HKLM\System\CurrentControlSet\Services\w810mgmt\DisplayName: &#8220;Cercsr6&#8243;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%WinDir%\$NtUninstallKB62478$
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\maya70docserver.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/rootkit/maya70docserver-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11269&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/rootkit/maya70docserver-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>INETACCELERATOR.EXE is Trojan Foreign</title>
		<link>http://greatis.com/blog/how-to-remove-malware/inetaccelerator-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/inetaccelerator-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 09:38:53 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Foreign]]></category>
		<category><![CDATA[INETACCELERATOR.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/inetaccelerator-exe.htm</guid>
		<description><![CDATA[The file INETACCELERATOR.EXE is malware related. You must delete the file INETACCELERATOR.EXE immediately! Delete the file INETACCELERATOR.EXE without delay! Kill the process INETACCELERATOR.EXE and remove INETACCELERATOR.EXE from the Windows startup. Malware Analysis of INETACCELERATOR.EXE Full path on a computer: %SYSTEM%\INETACCELERATOR.EXE Detected by RegRun Warrior: INETACCELERATOR.EXE Default location: %SYSTEM%\INETACCELERATOR.EXE Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>INETACCELERATOR.EXE</b> is malware related.<br />
You must delete the file <b>INETACCELERATOR.EXE</b> immediately!<br />
Delete the file <b>INETACCELERATOR.EXE</b> without delay!<br />
Kill the process <b>INETACCELERATOR.EXE</b> and remove <b>INETACCELERATOR.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of INETACCELERATOR.EXE<br />
Full path on a computer: %SYSTEM%\INETACCELERATOR.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p><b>INETACCELERATOR.EXE</b><br />
Default location: %SYSTEM%\INETACCELERATOR.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>INETACCELERATOR.EXE</strong>  is known as:</h3>
<p>Trojan.Foreign</p>
<h3><strong>INETACCELERATOR.EXE</strong> hash:</h3>
<ul>
<li>MD5: 95b6951075b43fae354217bb57c07427
</div>
<div id="clist">
How to quickly detect <strong>INETACCELERATOR.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SYSTEM%\INETACCELERATOR.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/inetaccelerator-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11267&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/inetaccelerator-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>_EX-68.EXE is Trojan Banload</title>
		<link>http://greatis.com/blog/how-to-remove-malware/_ex-68-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/_ex-68-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 09:35:03 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Banload]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[_EX-68.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/_ex-68-exe.htm</guid>
		<description><![CDATA[We checked some samples of _EX-68.EXE and detected the file _EX-68.EXE as threat. Remove the _EX-68.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of _EX-68.EXE Full path on a computer: %Windir%\Temp\_ex-68.exe Detected by RegRun Warrior: _EX-68.EXE Default location: %Windir%\Temp\_ex-68.exe Removal Results: Success Number of reboot: 1 _EX-68.EXE is known as: Trojan.Banload [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>_EX-68.EXE</b>  and detected the file <b>_EX-68.EXE</b> as threat.<br />
Remove the <b>_EX-68.EXE</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of _EX-68.EXE<br />
Full path on a computer: %Windir%\Temp\_ex-68.exe </h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p><b>_EX-68.EXE</b><br />
Default location: %Windir%\Temp\_ex-68.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>_EX-68.EXE</strong>  is known as:</h3>
<p>Trojan.Banload</p>
<h3><strong>_EX-68.EXE</strong> hash:</h3>
<ul>
<li>MD5: a7e4e91ebd829c972fd5b6fc38b957cf
</div>
<div id="clist">
How to quickly detect <strong>_EX-68.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MozillaAgent: &#8220;%Windir%\temp\_ex-68.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Temp%\1.tmp
<li>%Windir%\Temp\_ex-68.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/_ex-68-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11265&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/_ex-68-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OTYTKF.EXE is Worm Palevo</title>
		<link>http://greatis.com/blog/worm/otytkf-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/otytkf-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 09:30:35 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[OTYTKF.EXE]]></category>
		<category><![CDATA[Palevo]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/otytkf-exe.htm</guid>
		<description><![CDATA[The file OTYTKF.EXE is malware related. You must delete the file OTYTKF.EXE immediately! Delete the file OTYTKF.EXE without delay! Kill the process OTYTKF.EXE and remove OTYTKF.EXE from the Windows startup. Malware Analysis of OTYTKF.EXE Full path on a computer: %UserProfile%\otytkf.exe Detected by UnHackMe: OTYTKF.EXE Default location: %UserProfile%\otytkf.exe Removal Results: Success Number of reboot: 1 OTYTKF.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>OTYTKF.EXE</b> is malware related.<br />
You must delete the file <b>OTYTKF.EXE</b> immediately!<br />
Delete the file <b>OTYTKF.EXE</b> without delay!<br />
Kill the process <b>OTYTKF.EXE</b> and remove <b>OTYTKF.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of OTYTKF.EXE<br />
Full path on a computer: %UserProfile%\otytkf.exe </h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>OTYTKF.EXE</b><br />
Default location: %UserProfile%\otytkf.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>OTYTKF.EXE</strong>  is known as:</h3>
<p>Worm.Palevo, Trojan.Rimecud</p>
<h3><strong>OTYTKF.EXE</strong> hash:</h3>
<ul>
<li>MD5: aad4dac994bf75727bc12b0555d529a8
</div>
<div id="clist">
How to quickly detect <strong>OTYTKF.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman: &#8220;%UserProfile%\otytkf.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%UserProfile%\otytkf.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/otytkf-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11263&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/otytkf-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FUNSHIONINSTALL.EXE is Trojan Delf</title>
		<link>http://greatis.com/blog/how-to-remove-malware/funshioninstall-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/funshioninstall-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 09:21:12 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Delf]]></category>
		<category><![CDATA[FUNSHIONINSTALL.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/funshioninstall-exe.htm</guid>
		<description><![CDATA[Is the file FUNSHIONINSTALL.EXE located on your computer? Then your computer is infected. We do suggest you should remove FUNSHIONINSTALL.EXE from your computer as soon as possible. FUNSHIONINSTALL.EXE is Trojan/Backdoor. Kill the process FUNSHIONINSTALL.EXE and remove FUNSHIONINSTALL.EXE from the Windows startup. Malware Analysis of FUNSHIONINSTALL.EXE Full path on a computer: %Temp%\FunshionInstall.exe Detected by RegRun Warrior: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Is the file <b>FUNSHIONINSTALL.EXE</b> located on your computer? Then your computer is infected.<br />
We do suggest you should remove <b>FUNSHIONINSTALL.EXE</b> from your computer as soon as possible.<br />
<b>FUNSHIONINSTALL.EXE</b> is Trojan/Backdoor.<br />
Kill the process <b>FUNSHIONINSTALL.EXE</b> and remove <b>FUNSHIONINSTALL.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of FUNSHIONINSTALL.EXE<br />
Full path on a computer: %Temp%\FunshionInstall.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p><b>FUNSHIONINSTALL.EXE</b><br />
Default location: %Temp%\FunshionInstall.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>FUNSHIONINSTALL.EXE</strong>  is known as:</h3>
<p>Trojan.Delf</p>
<h3><strong>FUNSHIONINSTALL.EXE</strong> hash:</h3>
<ul>
<li>MD5: c56e9f57356f0f48e1022ba6901aa608
</div>
<div id="clist">
How to quickly detect <strong>FUNSHIONINSTALL.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Temp%\FunshionInstall.exe
<li>%Temp%\FunshionInstall.exe.ini
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/funshioninstall-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11261&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/funshioninstall-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MAXTUDOXDB.EXE is Trojan CFI</title>
		<link>http://greatis.com/blog/how-to-remove-malware/maxtudoxdb-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/maxtudoxdb-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 04:25:53 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[CFI]]></category>
		<category><![CDATA[MAXTUDOXDB.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/maxtudoxdb-exe.htm</guid>
		<description><![CDATA[We checked up the file MAXTUDOXDB.EXE and found it hazardous. The file MAXTUDOXDB.EXE must be deleted from the system immediately. Kill the process MAXTUDOXDB.EXE and remove MAXTUDOXDB.EXE from the Windows startup. Malware Analysis of MAXTUDOXDB.EXE Full path on a computer: C:\MAXTUDOXDB.exe Detected by UnHackMe: Item Name: MAXTUDOXDB Author: Unknown Related File: C:\\MAXTUDOXDB.EXE Type: Registry Run [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>MAXTUDOXDB.EXE</b> and found it hazardous.<br />
The file <b>MAXTUDOXDB.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>MAXTUDOXDB.EXE</b> and remove <b>MAXTUDOXDB.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of MAXTUDOXDB.EXE<br />
Full path on a computer: C:\MAXTUDOXDB.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: MAXTUDOXDB<br />
Author: Unknown<br />
Related File: C:\\MAXTUDOXDB.EXE<br />
Type: Registry Run</p>
<p>Item Name: MAXTUDOXDB.exe<br />
Author: Unknown<br />
Related File: C:\MAXTUDOXDB.EXE<br />
Type: Running Processes</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>MAXTUDOXDB.EXE</strong>  is known as:</h3>
<p>Trojan.CFI, Trojan.Toxaic</p>
<h3><strong>MAXTUDOXDB.EXE</strong> hash:</h3>
<ul>
<li>MD5: 8d51a95f4886a35e3b3f50da393602d4
</div>
<div id="clist">
How to quickly detect <strong>MAXTUDOXDB.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MAXTUDOXDB: &#8220;C:\\MAXTUDOXDB.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>C:\MAXTUDOXDB.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/maxtudoxdb-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11259&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/maxtudoxdb-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MSDSCSC.EXE is Backdoor Finlosky</title>
		<link>http://greatis.com/blog/backdoor/msdscsc-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/msdscsc-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 03:44:06 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[Finlosky]]></category>
		<category><![CDATA[MSDSCSC.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/msdscsc-exe.htm</guid>
		<description><![CDATA[The program MSDSCSC.EXE is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with MSDSCSC.EXE. Download for free: http://www.unhackme.com Malware Analysis of MSDSCSC.EXE Full path on a computer: %Personal%\MSDCSC\msdscsc.exe Detected by UnHackMe: Item Name: UserInit Author: Unknown Related File: %SysDir%\userinit.exe,%Personal%\MSDCSC\msdscsc.exe Type: UserInit Value [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>MSDSCSC.EXE</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>MSDSCSC.EXE</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of MSDSCSC.EXE<br />
Full path on a computer: %Personal%\MSDCSC\msdscsc.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: UserInit<br />
Author: Unknown<br />
Related File: %SysDir%\userinit.exe,%Personal%\MSDCSC\msdscsc.exe<br />
Type: UserInit Value</p>
<p>Item Name: MicroUpdate<br />
Author: Microsoft Corp.<br />
Related File: %PERSONAL%\MSDCSC\MSDSCSC.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>MSDSCSC.EXE</strong>  is known as:</h3>
<p>Backdoor.Finlosky, Backdoor.Krademok</p>
<h3><strong>MSDSCSC.EXE</strong> hash:</h3>
<ul>
<li>MD5: a4bbbebd9bb26f02a0a7bb7092ac3d06
</div>
<div id="clist">The file tries to connect to the dangerous web site.</div>
<div id="clist">
How to quickly detect <strong>MSDSCSC.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MicroUpdate: &#8220;%Personal%\MSDCSC\msdscsc.exe&#8221;
<li>HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: &#8220;%SysDir%\userinit.exe,%Personal%\MSDCSC\msdscsc.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Personal%\MSDCSC\msdscsc.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/msdscsc-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11257&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/msdscsc-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PLUGIN01.EXE is Trojan Banker</title>
		<link>http://greatis.com/blog/how-to-remove-malware/plugin01-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/plugin01-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 03:36:49 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Banker]]></category>
		<category><![CDATA[PLUGIN01.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/plugin01-exe.htm</guid>
		<description><![CDATA[The file PLUGIN01.EXE is malware related. You must delete the file PLUGIN01.EXE immediately! Delete the file PLUGIN01.EXE without delay! Kill the process PLUGIN01.EXE and remove PLUGIN01.EXE from the Windows startup. Malware Analysis of PLUGIN01.EXE Full path on a computer: %WinDir%\plugin01.exe Detected by UnHackMe: Item Name: Author: Unknown Related File: %WinDir%\DISKETE.EXE Type: Registry Run Item Name: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>PLUGIN01.EXE</b> is malware related.<br />
You must delete the file <b>PLUGIN01.EXE</b> immediately!<br />
Delete the file <b>PLUGIN01.EXE</b> without delay!<br />
Kill the process <b>PLUGIN01.EXE</b> and remove <b>PLUGIN01.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of PLUGIN01.EXE<br />
Full path on a computer: %WinDir%\plugin01.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name:<br />
Author: Unknown<br />
Related File: %WinDir%\DISKETE.EXE<br />
Type: Registry Run</p>
<p>Item Name: Plugin Live 64<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN64.EXE<br />
Type: Registry Run</p>
<p>Item Name:  Windows Plugin Two<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN02.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Plugin Three<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN03.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Plugin One<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN01.EXE<br />
Type: Registry Run</p>
<p>Item Name: plugin64.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN64.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin02.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN02.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin03.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN03.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin01.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN01.EXE<br />
Type: Running Processes</p>
<p>Item Name: Flash Plugin<br />
Author: Unknown<br />
Related File: %WinDir%\FLASH-PLUGIN.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>PLUGIN01.EXE</strong>  is known as:</h3>
<p>Trojan.Banker</p>
<h3><strong>PLUGIN01.EXE</strong> hash:</h3>
<ul>
<li>MD5: d3a84975c627bc0ff3d8ae7dd0901b3d
</div>
<div id="clist">The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.</div>
<div id="clist">
How to quickly detect <strong>PLUGIN01.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\: &#8220;%WinDir%\diskete.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Flash Plugin: &#8220;%WinDir%\flash-plugin.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Plugin Live 64: &#8220;%WinDir%\plugin64.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ Windows Plugin Two: &#8220;%WinDir%\plugin02.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Plugin Three: &#8220;%WinDir%\plugin03.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Plugin One: &#8220;%WinDir%\plugin01.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\Fonts\eugvx.exe
<li>%WinDir%\Fonts\iqpgi.exe
<li>%WinDir%\Fonts\jtuuy.exe
<li>%WinDir%\Fonts\lnmwm.exe
<li>%WinDir%\Fonts\tcira.exe
<li>%WinDir%\Fonts\vgdmr.exe
<li>%WinDir%\Fonts\wwxtl.exe
<li>%WinDir%\diskete.exe
<li>%WinDir%\flash-plugin.exe
<li>%WinDir%\plugin01.exe
<li>%WinDir%\plugin02.exe
<li>%WinDir%\plugin03.exe
<li>%WinDir%\plugin64.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/plugin01-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11255&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/plugin01-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PLUGIN03.EXE is Trojan Banker</title>
		<link>http://greatis.com/blog/how-to-remove-malware/plugin03-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/plugin03-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 03:31:33 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Banker]]></category>
		<category><![CDATA[PLUGIN03.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/plugin03-exe.htm</guid>
		<description><![CDATA[We checked some samples of PLUGIN02.EXE and detected the file PLUGIN02.EXE as threat. Remove the PLUGIN02.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of PLUGIN03.EXE Full path on a computer: %WinDir%\plugin03.exe Detected by UnHackMe: Item Name: Author: Unknown Related File: %WinDir%\DISKETE.EXE Type: Registry Run Item Name: Plugin Live 64 Author: Unknown [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>PLUGIN02.EXE</b>  and detected the file <b>PLUGIN02.EXE</b> as threat.<br />
Remove the <b>PLUGIN02.EXE</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of PLUGIN03.EXE<br />
Full path on a computer: %WinDir%\plugin03.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name:<br />
Author: Unknown<br />
Related File: %WinDir%\DISKETE.EXE<br />
Type: Registry Run</p>
<p>Item Name: Plugin Live 64<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN64.EXE<br />
Type: Registry Run</p>
<p>Item Name:  Windows Plugin Two<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN02.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Plugin Three<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN03.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Plugin One<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN01.EXE<br />
Type: Registry Run</p>
<p>Item Name: plugin64.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN64.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin02.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN02.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin03.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN03.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin01.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN01.EXE<br />
Type: Running Processes</p>
<p>Item Name: Flash Plugin<br />
Author: Unknown<br />
Related File: %WinDir%\FLASH-PLUGIN.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>PLUGIN03.EXE</strong>  is known as:</h3>
<p>Trojan.Banker, Trojan.Scar</p>
<h3><strong>PLUGIN03.EXE</strong> hash:</h3>
<ul>
<li>MD5: 08fe5e2da71ddaf37597b029f6442fa2
</div>
<div id="clist">The file tries to connect to the dangerous web site.</div>
<div id="clist">
How to quickly detect <strong>PLUGIN03.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\: &#8220;%WinDir%\diskete.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Flash Plugin: &#8220;%WinDir%\flash-plugin.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Plugin Live 64: &#8220;%WinDir%\plugin64.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ Windows Plugin Two: &#8220;%WinDir%\plugin02.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Plugin Three: &#8220;%WinDir%\plugin03.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Plugin One: &#8220;%WinDir%\plugin01.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\Fonts\eugvx.exe
<li>%WinDir%\Fonts\iqpgi.exe
<li>%WinDir%\Fonts\jtuuy.exe
<li>%WinDir%\Fonts\lnmwm.exe
<li>%WinDir%\Fonts\tcira.exe
<li>%WinDir%\Fonts\vgdmr.exe
<li>%WinDir%\Fonts\wwxtl.exe
<li>%WinDir%\diskete.exe
<li>%WinDir%\flash-plugin.exe
<li>%WinDir%\plugin01.exe
<li>%WinDir%\plugin02.exe
<li>%WinDir%\plugin03.exe
<li>%WinDir%\plugin64.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/plugin03-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11253&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/plugin03-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PLUGIN02.EXE is Trojan Scar</title>
		<link>http://greatis.com/blog/how-to-remove-malware/plugin02-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/plugin02-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 03:27:17 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[PLUGIN02.EXE]]></category>
		<category><![CDATA[Scar]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/plugin02-exe.htm</guid>
		<description><![CDATA[The file PLUGIN02.EXE is malware related. You must delete the file PLUGIN02.EXE immediately! Delete the file PLUGIN02.EXE without delay! Kill the process PLUGIN02.EXE and remove PLUGIN02.EXE from the Windows startup. Malware Analysis of PLUGIN02.EXE Full path on a computer: %WinDir%\plugin02.exe Detected by UnHackMe: Item Name: Author: Unknown Related File: %WinDir%\DISKETE.EXE Type: Registry Run Item Name: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>PLUGIN02.EXE</b> is malware related.<br />
You must delete the file <b>PLUGIN02.EXE</b> immediately!<br />
Delete the file <b>PLUGIN02.EXE</b> without delay!<br />
Kill the process <b>PLUGIN02.EXE</b> and remove <b>PLUGIN02.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of PLUGIN02.EXE<br />
Full path on a computer: %WinDir%\plugin02.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name:<br />
Author: Unknown<br />
Related File: %WinDir%\DISKETE.EXE<br />
Type: Registry Run</p>
<p>Item Name: Plugin Live 64<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN64.EXE<br />
Type: Registry Run</p>
<p>Item Name:  Windows Plugin Two<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN02.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Plugin Three<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN03.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Plugin One<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN01.EXE<br />
Type: Registry Run</p>
<p>Item Name: plugin64.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN64.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin02.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN02.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin03.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN03.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin01.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN01.EXE<br />
Type: Running Processes</p>
<p>Item Name: Flash Plugin<br />
Author: Unknown<br />
Related File: %WinDir%\FLASH-PLUGIN.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>PLUGIN02.EXE</strong>  is known as:</h3>
<p>Trojan.Scar</p>
<h3><strong>PLUGIN02.EXE</strong> hash:</h3>
<ul>
<li>MD5: 0f0f4c6fc34d387b557980288b730df5
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>PLUGIN02.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\: &#8220;%WinDir%\diskete.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Flash Plugin: &#8220;%WinDir%\flash-plugin.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Plugin Live 64: &#8220;%WinDir%\plugin64.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ Windows Plugin Two: &#8220;%WinDir%\plugin02.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Plugin Three: &#8220;%WinDir%\plugin03.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Plugin One: &#8220;%WinDir%\plugin01.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\Fonts\eugvx.exe
<li>%WinDir%\Fonts\iqpgi.exe
<li>%WinDir%\Fonts\jtuuy.exe
<li>%WinDir%\Fonts\lnmwm.exe
<li>%WinDir%\Fonts\tcira.exe
<li>%WinDir%\Fonts\vgdmr.exe
<li>%WinDir%\Fonts\wwxtl.exe
<li>%WinDir%\diskete.exe
<li>%WinDir%\flash-plugin.exe
<li>%WinDir%\plugin01.exe
<li>%WinDir%\plugin02.exe
<li>%WinDir%\plugin03.exe
<li>%WinDir%\plugin64.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/plugin02-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11251&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/plugin02-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PLUGIN64.EXE is Trojan Bancos</title>
		<link>http://greatis.com/blog/how-to-remove-malware/plugin64-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/plugin64-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 03:23:27 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Bancos]]></category>
		<category><![CDATA[PLUGIN64.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/plugin64-exe.htm</guid>
		<description><![CDATA[Is the file PLUGIN64.EXE located on your computer? Then your computer is infected. We do suggest you should remove PLUGIN64.EXE from your computer as soon as possible. PLUGIN64.EXE is Trojan/Backdoor. Kill the process PLUGIN64.EXE and remove PLUGIN64.EXE from the Windows startup. Malware Analysis of PLUGIN64.EXE Full path on a computer: %WinDir%\plugin64.exe Detected by UnHackMe: Item [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Is the file <b>PLUGIN64.EXE</b> located on your computer? Then your computer is infected.<br />
We do suggest you should remove <b>PLUGIN64.EXE</b> from your computer as soon as possible.<br />
<b>PLUGIN64.EXE</b> is Trojan/Backdoor.<br />
Kill the process <b>PLUGIN64.EXE</b> and remove <b>PLUGIN64.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of PLUGIN64.EXE<br />
Full path on a computer: %WinDir%\plugin64.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name:<br />
Author: Unknown<br />
Related File: %WinDir%\DISKETE.EXE<br />
Type: Registry Run</p>
<p>Item Name: Plugin Live 64<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN64.EXE<br />
Type: Registry Run</p>
<p>Item Name:  Windows Plugin Two<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN02.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Plugin Three<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN03.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Plugin One<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN01.EXE<br />
Type: Registry Run</p>
<p>Item Name: plugin64.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN64.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin02.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN02.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin03.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN03.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin01.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN01.EXE<br />
Type: Running Processes</p>
<p>Item Name: Flash Plugin<br />
Author: Unknown<br />
Related File: %WinDir%\FLASH-PLUGIN.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>PLUGIN64.EXE</strong>  is known as:</h3>
<p>Trojan.Bancos</p>
<h3><strong>PLUGIN64.EXE</strong> hash:</h3>
<ul>
<li>MD5: 663b9da0ee94180cd06ad8ec90dcdc1e
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>PLUGIN64.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\: &#8220;%WinDir%\diskete.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Flash Plugin: &#8220;%WinDir%\flash-plugin.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Plugin Live 64: &#8220;%WinDir%\plugin64.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ Windows Plugin Two: &#8220;%WinDir%\plugin02.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Plugin Three: &#8220;%WinDir%\plugin03.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Plugin One: &#8220;%WinDir%\plugin01.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\Fonts\eugvx.exe
<li>%WinDir%\Fonts\iqpgi.exe
<li>%WinDir%\Fonts\jtuuy.exe
<li>%WinDir%\Fonts\lnmwm.exe
<li>%WinDir%\Fonts\tcira.exe
<li>%WinDir%\Fonts\vgdmr.exe
<li>%WinDir%\Fonts\wwxtl.exe
<li>%WinDir%\diskete.exe
<li>%WinDir%\flash-plugin.exe
<li>%WinDir%\plugin01.exe
<li>%WinDir%\plugin02.exe
<li>%WinDir%\plugin03.exe
<li>%WinDir%\plugin64.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/plugin64-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11249&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/plugin64-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DISKETE.EXE is BackDoor DirtJump</title>
		<link>http://greatis.com/blog/backdoor/diskete-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/diskete-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 03:18:58 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[DirtJump]]></category>
		<category><![CDATA[DISKETE.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/diskete-exe.htm</guid>
		<description><![CDATA[The program DISKETE.EXE is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with DISKETE.EXE. Download for free: http://www.unhackme.com Malware Analysis of DISKETE.EXE Full path on a computer: %WinDir%\diskete.exe Detected by UnHackMe: Item Name: Author: Unknown Related File: %WinDir%\DISKETE.EXE Type: Registry Run Item [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>DISKETE.EXE</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>DISKETE.EXE</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of DISKETE.EXE<br />
Full path on a computer: %WinDir%\diskete.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name:<br />
Author: Unknown<br />
Related File: %WinDir%\DISKETE.EXE<br />
Type: Registry Run</p>
<p>Item Name: Plugin Live 64<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN64.EXE<br />
Type: Registry Run</p>
<p>Item Name:  Windows Plugin Two<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN02.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Plugin Three<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN03.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Plugin One<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN01.EXE<br />
Type: Registry Run</p>
<p>Item Name: plugin64.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN64.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin02.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN02.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin03.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN03.EXE<br />
Type: Running Processes</p>
<p>Item Name: plugin01.exe<br />
Author: Unknown<br />
Related File: %WinDir%\PLUGIN01.EXE<br />
Type: Running Processes</p>
<p>Item Name: Flash Plugin<br />
Author: Unknown<br />
Related File: %WinDir%\FLASH-PLUGIN.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>DISKETE.EXE</strong>  is known as:</h3>
<p>BackDoor.DirtJump, Trojan.Sisron, Trojan.Scar</p>
<h3><strong>DISKETE.EXE</strong> hash:</h3>
<ul>
<li>MD5: 2a2db1107f779c5015657358fcbca67e
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>DISKETE.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\: &#8220;%WinDir%\diskete.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Flash Plugin: &#8220;%WinDir%\flash-plugin.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Plugin Live 64: &#8220;%WinDir%\plugin64.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ Windows Plugin Two: &#8220;%WinDir%\plugin02.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Plugin Three: &#8220;%WinDir%\plugin03.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Plugin One: &#8220;%WinDir%\plugin01.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\Fonts\eugvx.exe
<li>%WinDir%\Fonts\iqpgi.exe
<li>%WinDir%\Fonts\jtuuy.exe
<li>%WinDir%\Fonts\lnmwm.exe
<li>%WinDir%\Fonts\tcira.exe
<li>%WinDir%\Fonts\vgdmr.exe
<li>%WinDir%\Fonts\wwxtl.exe
<li>%WinDir%\diskete.exe
<li>%WinDir%\flash-plugin.exe
<li>%WinDir%\plugin01.exe
<li>%WinDir%\plugin02.exe
<li>%WinDir%\plugin03.exe
<li>%WinDir%\plugin64.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/diskete-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11247&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/diskete-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MTEFQ2.EXE is Trojan Swizzor</title>
		<link>http://greatis.com/blog/how-to-remove-malware/mtefq2-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/mtefq2-exe.htm#comments</comments>
		<pubDate>Thu, 09 Feb 2012 02:48:01 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[MTEFQ2.EXE]]></category>
		<category><![CDATA[Swizzor]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/mtefq2-exe.htm</guid>
		<description><![CDATA[We checked up the file MTEFQ2.EXE and found it hazardous. The file MTEFQ2.EXE must be deleted from the system immediately. Kill the process MTEFQ2.EXE and remove MTEFQ2.EXE from the Windows startup. Malware Analysis of MTEFQ2.EXE Full path on a computer: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\mtefq2.exe Detected by UnHackMe: Item Name: shell Author: Unknown Related File: explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\mtefq2.exe Type: User Shell [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>MTEFQ2.EXE</b> and found it hazardous.<br />
The file <b>MTEFQ2.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>MTEFQ2.EXE</b> and remove <b>MTEFQ2.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of MTEFQ2.EXE<br />
Full path on a computer: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\mtefq2.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: shell<br />
Author: Unknown<br />
Related File: explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\mtefq2.exe<br />
Type: User Shell</p>
<p>Item Name: taskman<br />
Author: Unknown<br />
Related File: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\MTEFQ2.EXE<br />
Type: Winlogon System</p>
<p>Item Name: etef5<br />
Author: Unknown<br />
Related File: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\MTEFQ2.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>MTEFQ2.EXE</strong>  is known as:</h3>
<p>Trojan.Swizzor, Trojan.Menti</p>
<h3><strong>MTEFQ2.EXE</strong> hash:</h3>
<ul>
<li>MD5: cb57093ebf453b5465c7badc58bf0ac0
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>MTEFQ2.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman: &#8220;C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\mtefq2.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\etef5: &#8220;C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\mtefq2.exe&#8221;
<li>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: &#8220;explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\mtefq2.exe&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\Desktop.ini
<li>C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0068\mtefq2.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/mtefq2-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11245&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/mtefq2-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WINPROXY.DLL is Rootkit ZeroAccess</title>
		<link>http://greatis.com/blog/rootkit/winproxy-dll-3308c706.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/rootkit/winproxy-dll-3308c706.htm#comments</comments>
		<pubDate>Wed, 08 Feb 2012 11:33:00 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[WINPROXY.DLL]]></category>
		<category><![CDATA[ZeroAccess]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/winproxy-dll-3308c706.htm</guid>
		<description><![CDATA[Rootkit WINPROXY.DLL is software that enables continued privileged access to a computer while actively hiding its presence. Detection and removal of WINPROXY.DLL may be a very difficult process. You should use anti-rootkit software to fix the WINPROXY.DLL problem. Malware Analysis of WINPROXY.DLL Full path on a computer: %SysDir%\winproxy.dll Detected by RegRun Warrior: WINPROXY.DLL Default location: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Rootkit <b>WINPROXY.DLL</b> is software that enables continued privileged access to a computer while actively hiding its presence.<br />
Detection and removal of <b>WINPROXY.DLL</b> may be a very difficult process.<br />
You should  use anti-rootkit software to fix the <b>WINPROXY.DLL</b> problem.</p>
<h2>Malware Analysis of WINPROXY.DLL<br />
Full path on a computer: %SysDir%\winproxy.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p><b>WINPROXY.DLL</b><br />
Default location: %SysDir%\winproxy.dll</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>WINPROXY.DLL</strong>  is known as:</h3>
<p>Rootkit.ZeroAccess, Trojan.Sirefef</p>
<h3><strong>WINPROXY.DLL</strong> hash:</h3>
<ul>
<li>MD5: b89cfbe8cb247b57d8c10adaa66b462b
</div>
<div id="clist">
How to quickly detect <strong>WINPROXY.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Services\epson_pm_rpcv2_02\Parameters\ServiceDll: &#8220;%systemroot%\system32\winproxy.dll&#8221;
<li>HKLM\System\CurrentControlSet\Services\epson_pm_rpcv2_02\Description: &#8220;New service would allow parents to control their children&#8217;s online activity.&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\wqxout: &#8220;%Profile%\wqxout.exe /L&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%WinDir%\$NtUninstallKB3057$
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Local Appdata%\3308c706\@
<li>%Local Appdata%\3308c706\X
<li>%Profile%\jdFfFL.exe
<li>%Profile%\wqxout.exe
<li>%WinDir%\assembly\GAC_MSIL\Desktop.ini
<li>%SysDir%\dds_log_trash.cmd
<li>%SysDir%\winproxy.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/rootkit/winproxy-dll-3308c706.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11242&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/rootkit/winproxy-dll-3308c706.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI.DLL is Rootkit ZeroAccess</title>
		<link>http://greatis.com/blog/rootkit/pci-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/rootkit/pci-dll.htm#comments</comments>
		<pubDate>Wed, 08 Feb 2012 11:00:18 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[PCI.DLL]]></category>
		<category><![CDATA[ZeroAccess]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/pci-dll.htm</guid>
		<description><![CDATA[Rootkit PCI.DLL is software that enables continued privileged access to a computer while actively hiding its presence. Detection and removal of PCI.DLL may be a very difficult process. You should use anti-rootkit software to fix the PCI.DLL problem. Malware Analysis of PCI.DLL Full path on a computer: %SysDir%\pci.dll Detected by RegRun Warrior: PCI.DLL Default location: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Rootkit <b>PCI.DLL</b> is software that enables continued privileged access to a computer while actively hiding its presence.<br />
Detection and removal of <b>PCI.DLL</b> may be a very difficult process.<br />
You should  use anti-rootkit software to fix the <b>PCI.DLL</b> problem.</p>
<h2>Malware Analysis of PCI.DLL<br />
Full path on a computer: %SysDir%\pci.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p><b>PCI.DLL</b><br />
Default location: %SysDir%\pci.dll</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>PCI.DLL</strong>  is known as:</h3>
<p>Rootkit.ZeroAccess, Trojan.Sirefef</p>
<h3><strong>PCI.DLL</strong> hash:</h3>
<ul>
<li>MD5: 11028c6a84a967070cb1286550f2058f
</div>
<div id="clist">
How to quickly detect <strong>PCI.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Services\orbpvr\Parameters\ServiceDll: &#8220;%systemroot%\system32\pci.dll&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%WinDir%\$NtUninstallKB62478$</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\dds_trash_log.cmd
<li>%SysDir%\pci.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/rootkit/pci-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11240&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/rootkit/pci-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NVNETBUS.DLL is Rootkit ZeroAccess</title>
		<link>http://greatis.com/blog/how-to-remove-malware/nvnetbus-dll-3308c706.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/nvnetbus-dll-3308c706.htm#comments</comments>
		<pubDate>Wed, 08 Feb 2012 10:33:23 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[NVNETBUS.DLL]]></category>
		<category><![CDATA[Sirefef.BP]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/nvnetbus-dll-3308c706.htm</guid>
		<description><![CDATA[Rootkit NVNETBUS.DLL is software that enables continued privileged access to a computer while actively hiding its presence. Detection and removal of NVNETBUS.DLL may be a very difficult process. You should use anti-rootkit software to fix the NVNETBUS.DLL problem. Malware Analysis of NVNETBUS.DLL Full path on a computer: %SysDir%\nvnetbus.dll Detected by UnHackMe: NVNETBUS.DLL Default location: %SysDir%\nvnetbus.dll [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Rootkit <strong>NVNETBUS.DLL</strong> is software that enables continued privileged access to a computer while actively hiding its presence.<br />
Detection and removal of <strong>NVNETBUS.DLL</strong> may be a very difficult process.<br />
You should  use anti-rootkit software to fix the <strong>NVNETBUS.DLL</strong> problem.</p>
<h2>Malware Analysis of NVNETBUS.DLL<br />
Full path on a computer: %SysDir%\nvnetbus.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><strong>NVNETBUS.DLL</strong><br />
Default location: %SysDir%\nvnetbus.dll</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>NVNETBUS.DLL</strong> is known as:</h3>
<p>Rootkit.ZeroAccess, Trojan.Sirefef</p>
<h3><strong>NVNETBUS.DLL</strong> hash:</h3>
<ul>
<li>MD5: b89cfbe8cb247b57d8c10adaa66b462b</li>
</ul>
</div>
<div id="clist">How to quickly detect <strong>NVNETBUS.DLL</strong> presence?&nbsp;</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" alt="" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Services\infrastructure\Parameters\ServiceDll: &#8220;%systemroot%\system32\nvnetbus.dll&#8221;</li>
<li>HKLM\System\CurrentControlSet\Services\infrastructure\ImagePath: &#8220;%SystemRoot%\system32\svchost.exe -k netsvcs&#8221;</li>
<li>HKLM\System\CurrentControlSet\Services\infrastructure\Description: &#8220;New service would allow parents to control their children&#8217;s online activity.&#8221;</li>
<li>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: &#8220;%Local Appdata%\3308c706\X&#8221;</li>
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" alt="" width="32" height="32" />Folders:</div>
<ul>
<li>%WinDir%\$NtUninstallKB3057$</li>
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" alt="" width="32" height="32" />Files:</div>
<ul>
<li>%Local Appdata%\3308c706\@</li>
<li>%Local Appdata%\3308c706\X</li>
<li>%WinDir%\assembly\GAC_MSIL\Desktop.ini</li>
<li>%SysDir%\dds_log_trash.cmd</li>
<li>%SysDir%\nvnetbus.dll</li>
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/nvnetbus-dll-3308c706.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11238&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/nvnetbus-dll-3308c706.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>1029.URL is Backdoor Morix</title>
		<link>http://greatis.com/blog/backdoor/1029-url.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/1029-url.htm#comments</comments>
		<pubDate>Wed, 08 Feb 2012 06:52:44 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[1029.URL]]></category>
		<category><![CDATA[Morix]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/1029-url.htm</guid>
		<description><![CDATA[The program 1029.URL is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with 1029.URL. Download for free: http://www.unhackme.com Malware Analysis of 1029.URL Full path on a computer: %Program Files%\%Program Files%\1029.URL Detected by UnHackMe: Item Name: laass.exe Author: Microsoft Corporation Related File: C:\PROGRA~1\%PROGR~1\LAASS.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>1029.URL</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>1029.URL</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of 1029.URL<br />
Full path on a computer: %Program Files%\%Program Files%\1029.URL</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: laass.exe<br />
Author: Microsoft Corporation<br />
Related File: C:\PROGRA~1\%PROGR~1\LAASS.EXE<br />
Type: Running Processes</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>1029.URL</strong>  is known as:</h3>
<p>Backdoor.Morix, Spyware.Ardakey, Adware.Tencent</p>
<h3><strong>1029.URL</strong> hash:</h3>
<ul>
<li>MD5: 99eb9beb71b1ffe5aa51f4bf8564ba0f
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>1029.URL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Services\WinAudio\ImagePath: &#8220;cmd.exe /c C:\PROGRA~1\%PROGR~1\Cest.bat&#8221;
<li>HKLM\System\CurrentControlSet\Services\WinAudio\DisplayName: &#8220;WinAudio&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Program Files%\%Program Files%
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Program Files%\%Program Files%\1029.URL
<li>%Program Files%\%Program Files%\1031.URL
<li>%Program Files%\%Program Files%\Cest.bat
<li>%Program Files%\%Program Files%\Dest.BAt
<li>%Program Files%\%Program Files%\laass.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/1029-url.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11236&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/1029-url.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GWXYABCDE.GIF is Backdoor Farfli</title>
		<link>http://greatis.com/blog/backdoor/gwxyabcde-gif.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/gwxyabcde-gif.htm#comments</comments>
		<pubDate>Wed, 08 Feb 2012 03:46:41 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[Farfli]]></category>
		<category><![CDATA[GWXYABCDE.GIF]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/gwxyabcde-gif.htm</guid>
		<description><![CDATA[We received the file GWXYABCDE.GIF and detected that GWXYABCDE.GIF is not good. GWXYABCDE.GIF is Adware. You should remove the file GWXYABCDE.GIF. Kill the process GWXYABCDE.GIF and remove GWXYABCDE.GIF from Windows. Malware Analysis of GWXYABCDE.GIF Full path on a computer: %Program Files%\Bwxy\Gwxyabcde.gif Detected by UnHackMe: Item Name: Vwxyab Defghijk Mno Author: Tencent Related File: %PROGRAM FILES%\BWXY\GWXYABCDE.GIF [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We received the file <b>GWXYABCDE.GIF</b> and detected that <b>GWXYABCDE.GIF</b> is not good.<br />
<b>GWXYABCDE.GIF</b> is Adware. You should remove the file <b>GWXYABCDE.GIF</b>.<br />
Kill the process <b>GWXYABCDE.GIF</b> and remove <b>GWXYABCDE.GIF</b> from Windows.</p>
<h2>Malware Analysis of GWXYABCDE.GIF<br />
Full path on a computer: %Program Files%\Bwxy\Gwxyabcde.gif</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Vwxyab Defghijk Mno<br />
Author: Tencent<br />
Related File: %PROGRAM FILES%\BWXY\GWXYABCDE.GIF<br />
Type: Svchost DLLs</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>GWXYABCDE.GIF</strong>  is known as:</h3>
<p>Backdoor.Farfli</p>
<h3><strong>GWXYABCDE.GIF</strong> hash:</h3>
<ul>
<li>MD5: 81da9161bfdab8f2ec59ff7532097c7d
</div>
<div id="clist">The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.</div>
<div id="clist">
How to quickly detect <strong>GWXYABCDE.GIF</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\Parameters\ServiceDll: &#8220;%Program Files%\Bwxy\Gwxyabcde.gif&#8221;
<li>HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\DisplayName: &#8220;Vwxyab Defghijk Mnopqrst Vwxy&#8221;
<li>HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\ObjectName: &#8220;LocalSystem&#8221;
<li>HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\Description: &#8220;Vwxyabcd Fghijklmn Pqrstuv Xyabcdef Hij&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Program Files%\Bwxy
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>C:\Documents and Settings\temp.gif
<li>C:\Documents and Settings\temp2.gif
<li>%Program Files%\Bwxy\Gwxyabcde.gif
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/gwxyabcde-gif.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11234&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/gwxyabcde-gif.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RLJLZ.EXE is Worm Palevo</title>
		<link>http://greatis.com/blog/worm/rljlz-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/rljlz-exe.htm#comments</comments>
		<pubDate>Wed, 08 Feb 2012 03:15:51 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[Palevo]]></category>
		<category><![CDATA[RLJLZ.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/rljlz-exe.htm</guid>
		<description><![CDATA[The file RLJLZ.EXE is a computer worm. The worm RLJLZ.EXE is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the RLJLZ.EXE problem as soon as possible! Delete the file RLJLZ.EXE from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>RLJLZ.EXE</b> is a computer worm.<br />
The worm <b>RLJLZ.EXE</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>RLJLZ.EXE</b> problem as soon as possible!<br />
Delete the file <b>RLJLZ.EXE</b> from all infected computers in your network.<br />
Set up your network firewall against <b>RLJLZ.EXE</b> intervention.</p>
<h2>Malware Analysis of RLJLZ.EXE<br />
Full path on a computer: %Appdata%\rljlz.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: taskman<br />
Author: Unknown<br />
Related File: %APPDATA%\RLJLZ.EXE<br />
Type: Winlogon System</p>
<p>Item Name: rljlz.exe<br />
Author: Unknown<br />
Related File: %APPDATA%\RLJLZ.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>RLJLZ.EXE</strong>  is known as:</h3>
<p>Worm.Palevo, Trojan.Rimecud, Trojan.Pincav</p>
<h3><strong>RLJLZ.EXE</strong> hash:</h3>
<ul>
<li>MD5: c0434902bd87094640b91639a051cae0
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>RLJLZ.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman: &#8220;%Appdata%\rljlz.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\rljlz.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/rljlz-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11232&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/rljlz-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A_V_AUTO.DLL is Trojan Agent</title>
		<link>http://greatis.com/blog/how-to-remove-malware/a_v_auto-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/a_v_auto-dll.htm#comments</comments>
		<pubDate>Wed, 08 Feb 2012 03:09:37 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Agent]]></category>
		<category><![CDATA[A_V_AUTO.DLL]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/a_v_auto-dll.htm</guid>
		<description><![CDATA[We checked up the file A_V_AUTO.DLL and found it hazardous. The file A_V_AUTO.DLL must be deleted from the system immediately. Kill the process A_V_AUTO.DLL and remove A_V_AUTO.DLL from the Windows startup. Malware Analysis of A_V_AUTO.DLL Full path on a computer: %Program Files Common%\Microsoft Shared\A_v_AuTo.dll Detected by UnHackMe: Item Name: Internet Author: Sysinternals &#8211; www.sysinternals.com Related [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>A_V_AUTO.DLL</b> and found it hazardous.<br />
The file <b>A_V_AUTO.DLL</b> must be deleted from the system immediately.<br />
Kill the process <b>A_V_AUTO.DLL</b> and remove <b>A_V_AUTO.DLL</b> from the Windows startup.</p>
<h2>Malware Analysis of A_V_AUTO.DLL<br />
Full path on a computer: %Program Files Common%\Microsoft Shared\A_v_AuTo.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Internet<br />
Author: Sysinternals &#8211; www.sysinternals.com<br />
Related File: %PROGRAM FILES COMMON%\MICROSOFT SHARED\SERVICES.EXE<br />
Type: Registry Run</p>
<p>Item Name: services.exe<br />
Author: Sysinternals &#8211; www.sysinternals.com<br />
Related File: %PROGRAM FILES COMMON%\MICROSOFT SHARED\SERVICES.EXE<br />
Type: Running Processes</p>
<p>Item Name: diskserver<br />
Author: FlashFXP<br />
Related File: %Program Files Common%\Microsoft Shared\A_v_AuTo.dll<br />
Type: Auto Services</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>A_V_AUTO.DLL</strong>  is known as:</h3>
<p>Trojan.Agent</p>
<h3><strong>A_V_AUTO.DLL</strong> hash:</h3>
<ul>
<li>MD5: e63c970e78c1425a880a92dca3555265
</div>
<div id="clist">
How to quickly detect <strong>A_V_AUTO.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Internet: &#8220;%Program Files Common%\Microsoft Shared\services.exe&#8221;
<li>HKLM\System\CurrentControlSet\Services\diskserver\ImagePath: &#8220;%Program Files Common%\Microsoft Shared\A_v_AuTo.dll&#8221;
<li>HKLM\System\CurrentControlSet\Services\diskserver\DisplayName: &#8220;windows Disk Manager&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Program Files Common%\Microsoft Shared\A_v_AuTo.dll
<li>%Program Files Common%\Microsoft Shared\A_v_DVD.dll
<li>%Program Files Common%\Microsoft Shared\A_v_TT.dll
<li>%Program Files Common%\Microsoft Shared\services.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/a_v_auto-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11230&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/a_v_auto-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TKLMNOPQR.JPG is Backdoor Farfli</title>
		<link>http://greatis.com/blog/backdoor/tklmnopqr-jpg.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/tklmnopqr-jpg.htm#comments</comments>
		<pubDate>Wed, 08 Feb 2012 02:50:42 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[Farfli]]></category>
		<category><![CDATA[TKLMNOPQR.JPG]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/tklmnopqr-jpg.htm</guid>
		<description><![CDATA[The program TKLMNOPQR.JPG is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with TKLMNOPQR.JPG. Download for free: http://www.unhackme.com Malware Analysis of TKLMNOPQR.JPG Full path on a computer: Detected by UnHackMe: Item Name: Jklmno Qrstuvwx Abc Author: Tencent Related File: %PROGRAM FILES%\OKLM\TKLMNOPQR.JPG Type: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>TKLMNOPQR.JPG</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>TKLMNOPQR.JPG</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a>
</p>
<h2>Malware Analysis of TKLMNOPQR.JPG<br />
Full path on a computer: </h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Jklmno Qrstuvwx Abc<br />
Author: Tencent<br />
Related File: %PROGRAM FILES%\OKLM\TKLMNOPQR.JPG<br />
Type: Svchost DLLs</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>TKLMNOPQR.JPG</strong>  is known as:</h3>
<p>Backdoor.Farfli</p>
<h3><strong>TKLMNOPQR.JPG</strong> hash:</h3>
<ul>
<li>MD5: 3f0686cd7c8d7ec919325409d3ab3fe8
</div>
<div id="clist">The file tries to connect to the dangerous web site.</div>
<div id="clist">
How to quickly detect <strong>TKLMNOPQR.JPG</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\116276615\Parameters\ServiceDll: &#8220;%Program Files%\Oklm\Tklmnopqr.jpg&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_JKLMNO_QRSTUVWX_ABC\0000\Service: &#8220;Jklmno Qrstuvwx Abc&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_JKLMNO_QRSTUVWX_ABC\0000\DeviceDesc: &#8220;Jklmno Qrstuvwx Abcdefgh Jklm&#8221;
<li>HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Parameters\ServiceDll: &#8220;%Program Files%\Oklm\Tklmnopqr.jpg&#8221;
<li>HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\DisplayName: &#8220;Jklmno Qrstuvwx Abcdefgh Jklm&#8221;
<li>HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Description: &#8220;Jklmnopq Stuvwxyab Defghij Lmnopqrs Uvw&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Program Files%\Oklm
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>C:\Documents and Settings\temp.gif
<li>C:\Documents and Settings\temp2.gif
<li>%Program Files%\Oklm\Tklmnopqr.jpg
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/tklmnopqr-jpg.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11228&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/tklmnopqr-jpg.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EVERVACCINE.EXE is Adware VirusCure</title>
		<link>http://greatis.com/blog/adware/evervaccine-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/adware/evervaccine-exe.htm#comments</comments>
		<pubDate>Tue, 07 Feb 2012 10:38:01 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[EVERVACCINE.EXE]]></category>
		<category><![CDATA[VirusCure]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/evervaccine-exe.htm</guid>
		<description><![CDATA[The file EVERVACCINE.EXE is a part of Fake Antiviral software. You must delete the file EVERVACCINE.EXE immediately! Delete the file EVERVACCINE.EXE without delay! Kill the process EVERVACCINE.EXE and remove EVERVACCINE.EXE from the Windows startup. Malware Analysis of EVERVACCINE.EXE Full path on a computer: %Program Files%\EverVaccine\EverVaccine.exe Detected by UnHackMe: Item Name: EverVaccineMain Author: Ebiz Networks Related [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>EVERVACCINE.EXE</b> is a part of Fake Antiviral software.<br />
You must delete the file <b>EVERVACCINE.EXE</b> immediately!<br />
Delete the file <b>EVERVACCINE.EXE</b> without delay!<br />
Kill the process <b>EVERVACCINE.EXE</b> and remove <b>EVERVACCINE.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of EVERVACCINE.EXE<br />
Full path on a computer: %Program Files%\EverVaccine\EverVaccine.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: EverVaccineMain<br />
Author: Ebiz Networks<br />
Related File: %PROGRAM FILES%\EVERVACCINE\EVERVACCINE.EXE<br />
Type: Registry Run</p>
<p>Item Name: EverVaccine.exe<br />
Author: Ebiz Networks<br />
Related File: %PROGRAM FILES%\EVERVACCINE\EVERVACCINE.EXE<br />
Type: Running Processes</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>EVERVACCINE.EXE</strong>  is known as:</h3>
<p>Adware.VirusCure</p>
<h3><strong>EVERVACCINE.EXE</strong> hash:</h3>
<ul>
<li>MD5: 10df4a038e393878435f4c4079eefc17
</div>
<div id="clist">The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.</div>
<div id="clist">
How to quickly detect <strong>EVERVACCINE.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\EverVaccineMain: &#8220;&#8221;%Program Files%\EverVaccine\EverVaccine.exe&#8221; /Scan&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Program Files%\EverVaccine
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Program Files%\EverVaccine\etc\EverVaccineFD.SYS
<li>%Program Files%\EverVaccine\etc\EverVaccineMon.exe
<li>%Program Files%\EverVaccine\etc\EverVaccineReg.exe
<li>%Program Files%\EverVaccine\etc\EverVaccineReport.exe
<li>%Program Files%\EverVaccine\EverVaccine.exe
<li>%Program Files%\EverVaccine\EverVaccineUpdate.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/adware/evervaccine-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11225&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/adware/evervaccine-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>QUESTBASIC.EXE is AdWare AdLoad</title>
		<link>http://greatis.com/blog/adware/questbasic-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/adware/questbasic-exe.htm#comments</comments>
		<pubDate>Tue, 07 Feb 2012 05:33:15 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[Adload]]></category>
		<category><![CDATA[QUESTBASIC.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/questbasic-exe.htm</guid>
		<description><![CDATA[We received the file QUESTBASIC.EXE and detected that QUESTBASIC.EXE is not good. QUESTBASIC.EXE is Adware. You should remove the file QUESTBASIC.EXE. Kill the process QUESTBASIC.EXE and remove QUESTBASIC.EXE from Windows. Malware Analysis of QUESTBASIC.EXE Full path on a computer: %Program Files%\QuestBasic\questbasic.exe Detected by UnHackMe: Item Name: QuestBasic Service Author: Related File: &#8220;%Program Files%\QuestBasic\questbasic.exe&#8221; &#8220;%Program Files%\QuestBasic\questbasic.dll&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We received the file <b>QUESTBASIC.EXE</b> and detected that <b>QUESTBASIC.EXE</b> is not good.<br />
<b>QUESTBASIC.EXE</b> is Adware. You should remove the file <b>QUESTBASIC.EXE</b>.<br />
Kill the process <b>QUESTBASIC.EXE</b> and remove <b>QUESTBASIC.EXE</b> from Windows.</p>
<h2>Malware Analysis of QUESTBASIC.EXE<br />
Full path on a computer: %Program Files%\QuestBasic\questbasic.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: QuestBasic Service<br />
Author:<br />
Related File: &#8220;%Program Files%\QuestBasic\questbasic.exe&#8221; &#8220;%Program Files%\QuestBasic\questbasic.dll&#8221; cilelilog zawuwesu<br />
Type: Auto Services</p>
<p>Item Name: questbasic.exe<br />
Author: Unknown<br />
Related File: %PROGRAM FILES%\QUESTBASIC\QUESTBASIC.EXE<br />
Type: Running Processes</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>QUESTBASIC.EXE</strong>  is known as:</h3>
<p>AdWare.AdLoad</p>
<h3><strong>QUESTBASIC.EXE</strong> hash:</h3>
<ul>
<li>MD5: 2033ba486c6255ea5c9794ff8e8af5c0
</div>
<div id="clist">
How to quickly detect <strong>QUESTBASIC.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Services\QuestBasic Service\ImagePath: &#8220;&#8221;%Program Files%\QuestBasic\questbasic.exe&#8221; &#8220;%Program Files%\QuestBasic\questbasic.dll&#8221; tehunuqi wajorupu&#8221;
<li>HKLM\System\CurrentControlSet\Services\QuestBasic Service\DisplayName: &#8220;QuestBasic Service&#8221;
<li>HKLM\System\CurrentControlSet\Services\QuestBasic Service\Description: &#8220;Update and control for QuestBasic&#8221;
<li>HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{86F14831-D88C-4BC8-B871-C8FB24D95D9B}\DisplayName: &#8220;QuestBasic&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Program Files%\QuestBasic
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Common Appdata%\QuestBasic\questbasic114.exe
<li>%Program Files%\QuestBasic\questbasic.dll
<li>%Program Files%\QuestBasic\questbasic.exe
<li>%Program Files%\QuestBasic\uninstall.exe
<li>%WinDir%\Temp\QUE7.tmp\upgrade.cab
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/adware/questbasic-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11218&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/adware/questbasic-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HDDLOF.EXE is Backdoor Yoddos</title>
		<link>http://greatis.com/blog/backdoor/hddlof-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/hddlof-exe.htm#comments</comments>
		<pubDate>Tue, 07 Feb 2012 03:11:01 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[HDDLOF.EXE]]></category>
		<category><![CDATA[Yoddos]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/hddlof-exe.htm</guid>
		<description><![CDATA[The program HDDLOF.EXE is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with HDDLOF.EXE. Download for free: http://www.unhackme.com Malware Analysis of HDDLOF.EXE Full path on a computer: %Program Files%\Internet Explorer\hddlof.exe Detected by UnHackMe: Item Name: Microsoft Updatembt.exe Author: (C)360.cn Inc.All Rights Reserved. [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>HDDLOF.EXE</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>HDDLOF.EXE</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of HDDLOF.EXE<br />
Full path on a computer: %Program Files%\Internet Explorer\hddlof.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Microsoft Updatembt.exe<br />
Author: (C)360.cn Inc.All Rights Reserved.<br />
Related File: %Program Files%\Internet Explorer\hddlof.exe<br />
Type: Auto Services</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>HDDLOF.EXE</strong>  is known as:</h3>
<p>Backdoor.Yoddos</p>
<h3><strong>HDDLOF.EXE</strong> hash:</h3>
<ul>
<li>MD5: bc1fdc8db7d10ab59167daeaf8685cc6
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>HDDLOF.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Services\Microsoft Updatembt.exe\ImagePath: &#8220;%Program Files%\Internet Explorer\hddlof.exe&#8221;
<li>HKLM\System\CurrentControlSet\Services\Microsoft Updatembt.exe\DisplayName: &#8220;Microsoft Updateqhe Software is private services&#8221;
<li>HKLM\System\CurrentControlSet\Services\Microsoft Updatembt.exe\Description: &#8220;Microsoft Providehpan Software Update services for windows.&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Program Files%\Internet Explorer\hddlof.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/hddlof-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11216&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/hddlof-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USB.EXE is Trojan Injector</title>
		<link>http://greatis.com/blog/how-to-remove-malware/usb-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/usb-exe.htm#comments</comments>
		<pubDate>Tue, 07 Feb 2012 02:42:00 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Injector]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[USB.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/usb-exe.htm</guid>
		<description><![CDATA[The file USB.EXE is identified as a virus dropper. The dropper USB.EXE is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center. The file USB.EXE loads into the computer memory and tries to connect to the dangerous web site. Usually the USB.EXE dropper does not infect the [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>USB.EXE</b> is identified as a virus dropper.<br />
The dropper <b>USB.EXE</b> is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.<br />
The file <b>USB.EXE</b> loads into the computer memory and tries to connect to the dangerous web site.<br />
Usually the  <b>USB.EXE</b> dropper does not infect the files on the computer and does not replicate itself on other computers.<br />
Kill the <b>USB.EXE</b> process and delete the file <b>USB.EXE</b>.</p>
<h2>Malware Analysis of USB.EXE<br />
Full path on a computer: %SysDir%\usb.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Supports RAS Connections<br />
Author: AVG Technologies CZ, s.r.o.<br />
Related File: %SysDir%\SVHOST.EXE<br />
Type: Registry Run</p>
<p>Item Name: Windows Data Serivce<br />
Author: VIT Software, LLC<br />
Related File: %WinDir%\DN.EXE<br />
Type: Registry Run</p>
<p>Item Name: svhost.exe<br />
Author: AVG Technologies CZ, s.r.o.<br />
Related File: %SYSDIR%\SVHOST.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<p>Item Name: dn.exe<br />
Author: VIT Software, LLC<br />
Related File: %WinDir%\DN.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<p>Item Name: Windows Service Agents<br />
Author: VIT Software, LLC<br />
Related File: %SysDir%\USB.EXE<br />
Type: Registry Run</p>
<p>Item Name: usb.exe<br />
Author: VIT Software, LLC<br />
Related File: %SYSDIR%\USB.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>USB.EXE</strong>  is known as:</h3>
<p>Trojan.Injector</p>
<h3><strong>USB.EXE</strong> hash:</h3>
<ul>
<li>MD5: 1e52c27ab0ab3fbc46873274b0bffac4
</div>
<div id="clist">The file tries to connect to the dangerous web site.</div>
<div id="clist">
How to quickly detect <strong>USB.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Supports RAS Connections: &#8220;svhost.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Service Agents: &#8220;usb.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Data Serivce: &#8220;dn.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Supports RAS Connections: &#8220;svhost.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Windows Service Agents: &#8220;usb.exe&#8221;
<li>HKLM\Software\Microsoft\yOLE\Supports RAS Connections: &#8220;svhost.exe&#8221;
<li>HKLM\System\CurrentControlSet\Control\Lsa\Supports RAS Connections: &#8220;svhost.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Supports RAS Connections: &#8220;svhost.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Service Agents: &#8220;usb.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices\Supports RAS Connections: &#8220;svhost.exe&#8221;
<li>HKCU\Software\Microsoft\yOLE\Supports RAS Connections: &#8220;svhost.exe&#8221;
<li>HKCU\SYSTEM\CurrentControlSet\Control\Lsa\Supports RAS Connections: &#8220;svhost.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\svhost.exe
<li>%SysDir%\usb.exe
<li>%WinDir%\dn.exe
<li>%WinDir%\nigzss.txt
<li>C:\msn.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/usb-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11214&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/usb-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FXGLDRV.DLL is Trojan Sefnit</title>
		<link>http://greatis.com/blog/how-to-remove-malware/fxgldrv-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/fxgldrv-dll.htm#comments</comments>
		<pubDate>Mon, 06 Feb 2012 03:41:19 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[FXGLDRV.DLL]]></category>
		<category><![CDATA[Sefnit]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/fxgldrv-dll.htm</guid>
		<description><![CDATA[Is the file FXGLDRV.DLL located on your computer? Then your computer is infected. We do suggest you should remove FXGLDRV.DLL from your computer as soon as possible. FXGLDRV.DLL is Trojan/Backdoor. Kill the process FXGLDRV.DLL and remove FXGLDRV.DLL from the Windows startup. Malware Analysis of FXGLDRV.DLL Full path on a computer: %Local Appdata%\AgereobjCtrl\fxGLdrv.dll Detected by UnHackMe: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Is the file <b>FXGLDRV.DLL</b> located on your computer? Then your computer is infected.<br />
We do suggest you should remove <b>FXGLDRV.DLL</b> from your computer as soon as possible.<br />
<b>FXGLDRV.DLL</b> is Trojan/Backdoor.<br />
Kill the process <b>FXGLDRV.DLL</b> and remove <b>FXGLDRV.DLL</b> from the Windows startup.</p>
<h2>Malware Analysis of FXGLDRV.DLL<br />
Full path on a computer: %Local Appdata%\AgereobjCtrl\fxGLdrv.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: fxGLdrv<br />
Author: Unknown<br />
Related File: %LOCAL APPDATA%\AGEREOBJCTRL\FXGLDRV.DLL<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>FXGLDRV.DLL</strong>  is known as:</h3>
<p>Trojan.Sefnit</p>
<h3><strong>FXGLDRV.DLL</strong> hash:</h3>
<ul>
<li>MD5: e9067f7bbeec4261dc4e3d84e937d96a
</div>
<div id="clist">
How to quickly detect <strong>FXGLDRV.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\fxGLdrv: &#8220;rundll32.exe &#8220;%Local Appdata%\AgereobjCtrl\fxGLdrv.dll&#8221;,wmiobjNetM QuickMouseppm&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Local Appdata%\AgereobjCtrl
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Local Appdata%\AgereobjCtrl\fxGLdrv.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/fxgldrv-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11212&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/fxgldrv-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TSYSTEM.EXE is Trojan Banload</title>
		<link>http://greatis.com/blog/how-to-remove-malware/tsystem-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/tsystem-exe.htm#comments</comments>
		<pubDate>Sun, 05 Feb 2012 04:03:29 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Banload]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[TSYSTEM.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/tsystem-exe.htm</guid>
		<description><![CDATA[The file TSYSTEM.EXE is malware related. You must delete the file TSYSTEM.EXE immediately! Delete the file TSYSTEM.EXE without delay! Kill the process TSYSTEM.EXE and remove TSYSTEM.EXE from the Windows startup. Malware Analysis of TSYSTEM.EXE Full path on a computer: %Local Appdata%\Noroeste\TSystem.exe Detected by UnHackMe: Item Name: TSystem.exe Author: FileSystem Related File: %LOCAL APPDATA%\NOROESTE\TSYSTEM.EXE Type: Registry [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>TSYSTEM.EXE</b> is malware related.<br />
You must delete the file <b>TSYSTEM.EXE</b> immediately!<br />
Delete the file <b>TSYSTEM.EXE</b> without delay!<br />
Kill the process <b>TSYSTEM.EXE</b> and remove <b>TSYSTEM.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of TSYSTEM.EXE<br />
Full path on a computer: %Local Appdata%\Noroeste\TSystem.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: TSystem.exe<br />
Author: FileSystem<br />
Related File: %LOCAL APPDATA%\NOROESTE\TSYSTEM.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>TSYSTEM.EXE</strong>  is known as:</h3>
<p>Trojan.Banload, Trojan.AVKill</p>
<h3><strong>TSYSTEM.EXE</strong> hash:</h3>
<ul>
<li>MD5: 81e22936e6157e08515ecf8541cf38af
</div>
<div id="clist">
How to quickly detect <strong>TSYSTEM.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\TSystem.exe: &#8220;%Local Appdata%\Noroeste\TSystem.exe&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Local Appdata%\Noroeste
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Local Appdata%\Noroeste\TSystem.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/tsystem-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=11152&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/tsystem-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

