<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Analysis and Removal</title>
	<atom:link href="http://greatis.com/blog/feed" rel="self" type="application/rss+xml" />
	<link>http://greatis.com/blog</link>
	<description>Malware Analysis and Removal</description>
	<lastBuildDate>Wed, 16 May 2012 12:12:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>LUA5.1-32.DLL</title>
		<link>http://greatis.com/blog/not-a-virus/lua5-1-32-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/not-a-virus/lua5-1-32-dll.htm#comments</comments>
		<pubDate>Wed, 16 May 2012 12:11:29 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Not-a-Virus]]></category>
		<category><![CDATA[LUA5.1-32.DLL]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/lua5-1-32-dll.htm</guid>
		<description><![CDATA[The file LUA5.1-32.DLL is not a virus. The program LUA5.1-32.DLL is a system security tool. But the LUA5.1-32.DLL tool may be used to compromise computer security by the hacker. Use the LUA5.1-32.DLL file at your own risk! You can delete the LUA5.1-32.DLL program from your computer with problems. Malware Analysis of LUA5.1-32.DLL Full path on [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>LUA5.1-32.DLL</b> is not a virus.<br />
The program <b>LUA5.1-32.DLL</b> is a system security tool.<br />
But the <b>LUA5.1-32.DLL</b> tool may be used to compromise computer security by the hacker.<br />
Use the <b>LUA5.1-32.DLL</b> file at your own risk!<br />
You can delete the <b>LUA5.1-32.DLL</b> program from your computer with problems.</p>
<h2>Malware Analysis of LUA5.1-32.DLL<br />
Full path on a computer: C:\temp\[hostex.org]\CETFF1.tmp\extracted\lua5.1-32.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>LUA5.1-32.DLL</b><br />
Default location: C:\temp\[hostex.org]\CETFF1.tmp\extracted\lua5.1-32.dll</p>
</div>
<div id="blist">
<h3><strong>LUA5.1-32.DLL</strong>  is known as:</h3>
<p>Not-a-Virus</p>
<h3><strong>LUA5.1-32.DLL</strong> hash:</h3>
<ul>
<li>MD5: 859be12ad1e4ace1418ff3a069b35115
</div>
<div id="clist">
How to quickly detect <strong>LUA5.1-32.DLL</strong> presence?</p>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>C:\temp\[hostex.org]
<li>C:\temp\[hostex.org]\CETFF1.tmp
<li>C:\temp\[hostex.org]\CETFF1.tmp\extracted
<li>C:\temp\[hostex.org]\CETFF1.tmp\extracted\win32
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>C:\temp\[hostex.org]\CETFF1.tmp\CET_Archive.dat
<li>C:\temp\[hostex.org]\CETFF1.tmp\extracted\defines.lua
<li>C:\temp\[hostex.org]\CETFF1.tmp\extracted\GHOSTv1,0.EXE
<li>C:\temp\[hostex.org]\CETFF1.tmp\extracted\lua5.1-32.dll
<li>C:\temp\[hostex.org]\CETFF1.tmp\extracted\win32\dbghelp.dll
<li>C:\temp\[hostex.org]\CETFF1.tmp\GHOSTv1,0.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/not-a-virus/lua5-1-32-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12670&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/not-a-virus/lua5-1-32-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NVSMART.EXE is Trojan Sasfis</title>
		<link>http://greatis.com/blog/how-to-remove-malware/nvsmart-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/nvsmart-exe.htm#comments</comments>
		<pubDate>Wed, 16 May 2012 10:32:01 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[NVSMART.EXE]]></category>
		<category><![CDATA[Sasfis]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/nvsmart-exe.htm</guid>
		<description><![CDATA[We checked up the file NVSMART.EXE and found it hazardous. The file NVSMART.EXE must be deleted from the system immediately. Kill the process NVSMART.EXE and remove NVSMART.EXE from the Windows startup. Malware Analysis of NVSMART.EXE Full path on a computer: %AllUsersProfile%\SxS\NvSmart.exe Detected by UnHackMe: NVSMART.EXE Default location: %AllUsersProfile%\SxS\NvSmart.exe Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>NVSMART.EXE</b> and found it hazardous.<br />
The file <b>NVSMART.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>NVSMART.EXE</b> and remove <b>NVSMART.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of NVSMART.EXE<br />
Full path on a computer: %AllUsersProfile%\SxS\NvSmart.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>NVSMART.EXE</b><br />
Default location: %AllUsersProfile%\SxS\NvSmart.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>NVSMART.EXE</strong>  is known as:</h3>
<p>Trojan.Sasfis</p>
<h3><strong>NVSMART.EXE</strong> hash:</h3>
<ul>
<li>MD5: 09b8b54f78a10c435cd319070aa13c28
</div>
<div id="clist">
How to quickly detect <strong>NVSMART.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\SYSTEM\CurrentControlSet\Services\Icmipv6\ImagePath: &#8220;&#8221;%AllUsersProfile%\SxS\NvSmart.exe&#8221; 200 0&#8243;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%AllUsersProfile%\SxS\boot.ldr
<li>%AllUsersProfile%\SxS\bug.log
<li>%AllUsersProfile%\SxS\NvSmart.exe
<li>%AllUsersProfile%\SxS\NvSmartMax.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/nvsmart-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12668&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/nvsmart-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WIN32.EXE is Backdoor Fynloski</title>
		<link>http://greatis.com/blog/backdoor/win32-exe-2.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/win32-exe-2.htm#comments</comments>
		<pubDate>Wed, 16 May 2012 10:23:39 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[Fynloski]]></category>
		<category><![CDATA[win32.exe]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/win32-exe-2.htm</guid>
		<description><![CDATA[The program WIN32.EXE is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with WIN32.EXE. Download for free: http://www.unhackme.com Malware Analysis of WIN32.EXE Full path on a computer: C:\MSDCSC\win32.exe Detected by UnHackMe: Item Name: UserInit Author: Unknown Related File: %SysDir%\userinit.exe,C:\MSDCSC\win32.exe Type: UserInit Value [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>WIN32.EXE</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>WIN32.EXE</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of WIN32.EXE<br />
Full path on a computer: C:\MSDCSC\win32.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: UserInit<br />
Author: Unknown<br />
Related File: %SysDir%\userinit.exe,C:\MSDCSC\win32.exe<br />
Type: UserInit Value</p>
<p>Item Name: System<br />
Author:<br />
Related File: C:\MSDCSC\WIN32.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>WIN32.EXE</strong>  is known as:</h3>
<p>Backdoor.Fynloski, Trojan.Injector, Backdoor.Poison, Trojan.VbCrypt</p>
<h3><strong>WIN32.EXE</strong> hash:</h3>
<ul>
<li>MD5: 3fa62a9fd01a9b3b6b9dc4802042eac1
</div>
<div id="clist">
How to quickly detect <strong>WIN32.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\System: &#8220;C:\MSDCSC\win32.exe&#8221;
<li>HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: &#8220;%SysDir%\userinit.exe,C:\MSDCSC\win32.exe&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>C:\MSDCSC
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>C:\MSDCSC\win32.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/win32-exe-2.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12666&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/win32-exe-2.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LIB32WAOO.EXE is Worm Roxin</title>
		<link>http://greatis.com/blog/worm/lib32waoo-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/lib32waoo-exe.htm#comments</comments>
		<pubDate>Wed, 16 May 2012 09:49:52 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[LIB32WAOO.EXE]]></category>
		<category><![CDATA[Roxin]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/lib32waoo-exe.htm</guid>
		<description><![CDATA[The file LIB32WAOO.EXE is a computer worm. The worm LIB32WAOO.EXE is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the LIB32WAOO.EXE problem as soon as possible! Delete the file LIB32WAOO.EXE from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>LIB32WAOO.EXE</b> is a computer worm.<br />
The worm <b>LIB32WAOO.EXE</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>LIB32WAOO.EXE</b> problem as soon as possible!<br />
Delete the file <b>LIB32WAOO.EXE</b> from all infected computers in your network.<br />
Set up your network firewall against <b>LIB32WAOO.EXE</b> intervention.</p>
<h2>Malware Analysis of LIB32WAOO.EXE<br />
Full path on a computer: %System%\lib32waoo.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>LIB32WAOO.EXE</b><br />
Default location: %System%\lib32waoo.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>LIB32WAOO.EXE</strong>  is known as:</h3>
<p>Worm.Roxin</p>
<h3><strong>LIB32WAOO.EXE</strong> hash:</h3>
<ul>
<li>MD5: 6eb5420eacd95d3def91cbea45da16f6
</div>
<div id="clist">
How to quickly detect <strong>LIB32WAOO.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WINDOWS\Temp\servcie11102F27.exe: &#8220;%Windir%\Temp\servcie11102F27.exe&#8221;
<li>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WINDOWS\Temp\servcie11103027.exe: &#8220;%Windir%\Temp\servcie11103027.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>c:\395500.dll
<li>%Profiles%\LocalService\Favorites\Desktop.ini
<li>c:\Net-Temp.ini
<li>c:\NT_Path.jpg
<li>%ProgramFiles%\133109\ms133234.dll
<li>%ProgramFiles%\133109\system
<li>%ProgramFiles%\Jbrj\Imhulawbk.bmp
<li>%System%\einuBGK.exe
<li>%System%\glswBGK.exe
<li>%System%\JTahovz.exe
<li>%System%\lib32waoo.exe
<li>%Windir%\Temp\servcie11103027.exe
<li>%System%\Rfmcthy.cc3
<li>%System%\rvAFJOT.exe
<li>%Windir%\Temp\servcie11102F27.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/lib32waoo-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12664&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/lib32waoo-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CBEVTSVC.EXE is Trojan Agent</title>
		<link>http://greatis.com/blog/how-to-remove-malware/cbevtsvc-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/cbevtsvc-exe.htm#comments</comments>
		<pubDate>Wed, 16 May 2012 03:59:47 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Agent]]></category>
		<category><![CDATA[CbEvtSvc.exe]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/cbevtsvc-exe.htm</guid>
		<description><![CDATA[We checked up the file CBEVTSVC.EXE and found it hazardous. The file CBEVTSVC.EXE must be deleted from the system immediately. Kill the process CBEVTSVC.EXE and remove CBEVTSVC.EXE from the Windows startup. Malware Analysis of CBEVTSVC.EXE Full path on a computer: %SysDir%\CbEvtSvc.exe Detected by UnHackMe: Item Name: CbEvtSvc Author: Related File: %WinDir%\System32\CbEvtSvc.exe -k netsvcs Type: Auto [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>CBEVTSVC.EXE</b> and found it hazardous.<br />
The file <b>CBEVTSVC.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>CBEVTSVC.EXE</b> and remove <b>CBEVTSVC.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of CBEVTSVC.EXE<br />
Full path on a computer: %SysDir%\CbEvtSvc.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: CbEvtSvc<br />
Author:<br />
Related File: %WinDir%\System32\CbEvtSvc.exe -k netsvcs<br />
Type: Auto Services</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>CBEVTSVC.EXE</strong>  is known as:</h3>
<p>Trojan.Agent, Trojan.Zlob, Trojan.Revelation</p>
<h3><strong>CBEVTSVC.EXE</strong> hash:</h3>
<ul>
<li>MD5: 69d105a56cc43f42dd32ef288a51d906
</div>
<div id="clist">
How to quickly detect <strong>CBEVTSVC.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_CBEVTSVC\0000\Service: &#8220;CbEvtSvc&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_CBEVTSVC\0000\DeviceDesc: &#8220;CbEvtSvc&#8221;
<li>HKLM\System\CurrentControlSet\Services\CbEvtSvc\ImagePath: &#8220;%SystemRoot%\System32\CbEvtSvc.exe -k netsvcs&#8221;
<li>HKLM\System\CurrentControlSet\Services\CbEvtSvc\DisplayName: &#8220;CbEvtSvc&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\CbEvtSvc.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/cbevtsvc-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12662&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/cbevtsvc-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TEMP90.EXE is Backdoor Kelihos</title>
		<link>http://greatis.com/blog/backdoor/temp90-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/temp90-exe.htm#comments</comments>
		<pubDate>Wed, 16 May 2012 03:27:27 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[Kelihos]]></category>
		<category><![CDATA[TEMP90.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/temp90-exe.htm</guid>
		<description><![CDATA[The program TEMP90.EXE is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with TEMP90.EXE. Download for free: http://www.unhackme.com Malware Analysis of TEMP90.EXE Full path on a computer: %WinDir%\Temp\temp90.exe Detected by UnHackMe: Item Name: AmdAgent Author: Unknown Related File: %WinDir%\TEMP\TEMP90.EXE Type: Registry Run [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>TEMP90.EXE</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>TEMP90.EXE</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of TEMP90.EXE<br />
Full path on a computer: %WinDir%\Temp\temp90.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: AmdAgent<br />
Author: Unknown<br />
Related File: %WinDir%\TEMP\TEMP90.EXE<br />
Type: Registry Run</p>
<p>Item Name: temp90.exe<br />
Author: Unknown<br />
Related File: %WinDir%\TEMP\TEMP90.EXE<br />
Type: Running Processes</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>TEMP90.EXE</strong>  is known as:</h3>
<p>Backdoor.Kelihos</p>
<h3><strong>TEMP90.EXE</strong> hash:</h3>
<ul>
<li>MD5: 3d58527bbad08796c9ec6ffa9b7e116b
</div>
<div id="clist">
How to quickly detect <strong>TEMP90.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\AmdAgent: &#8220;%WinDir%\Temp\temp90.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\drivers\npf.sys
<li>%SysDir%\Packet.dll
<li>%SysDir%\wpcap.dll
<li>%WinDir%\Temp\temp90.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/temp90-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12660&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/temp90-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HGOGLE.EXE is Backdoor Poison</title>
		<link>http://greatis.com/blog/backdoor/hgogle-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/hgogle-exe.htm#comments</comments>
		<pubDate>Tue, 15 May 2012 07:32:24 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[HGOGLE.EXE]]></category>
		<category><![CDATA[Poison]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/hgogle-exe.htm</guid>
		<description><![CDATA[The program HGOGLE.EXE is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with HGOGLE.EXE. Download for free: http://www.unhackme.com Malware Analysis of HGOGLE.EXE Full path on a computer: %System%\hgogle.exe Detected by UnHackMe: HGOGLE.EXE Default location: %System%\hgogle.exe Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>HGOGLE.EXE</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>HGOGLE.EXE</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of HGOGLE.EXE<br />
Full path on a computer: %System%\hgogle.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>HGOGLE.EXE</b><br />
Default location: %System%\hgogle.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>HGOGLE.EXE</strong>  is known as:</h3>
<p>Backdoor.Poison</p>
<h3><strong>HGOGLE.EXE</strong> hash:</h3>
<ul>
<li>MD5: dcf5c725c908548b3f32c97533f9e5ea
</div>
<div id="clist">
How to quickly detect <strong>HGOGLE.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{BA8415FC-57D2-132F-1BC1-DAB924800386}\StubPath: &#8220;%System%\hgogle.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%System%\hgogle.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/hgogle-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12658&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/hgogle-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ANTIWPA.DLL is Not-a-Virus HackTool.Wpakill</title>
		<link>http://greatis.com/blog/not-a-virus/antiwpa-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/not-a-virus/antiwpa-dll.htm#comments</comments>
		<pubDate>Tue, 15 May 2012 05:58:14 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Not-a-Virus]]></category>
		<category><![CDATA[ANTIWPA.DLL]]></category>
		<category><![CDATA[HackTool.Wpakill]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/antiwpa-dll.htm</guid>
		<description><![CDATA[The file ANTIWPA.DLL is not a virus. The program ANTIWPA.DLL is a system security tool. But the ANTIWPA.DLL tool may be used to compromise computer security by the hacker. Use the ANTIWPA.DLL file at your own risk! You can delete the ANTIWPA.DLL program from your computer with problems. Malware Analysis of ANTIWPA.DLL Full path on [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>ANTIWPA.DLL</b> is not a virus.<br />
The program <b>ANTIWPA.DLL</b> is a system security tool.<br />
But the <b>ANTIWPA.DLL</b> tool may be used to compromise computer security by the hacker.<br />
Use the <b>ANTIWPA.DLL</b> file at your own risk!<br />
You can delete the <b>ANTIWPA.DLL</b> program from your computer with problems.</p>
<h2>Malware Analysis of ANTIWPA.DLL<br />
Full path on a computer: %SysDir%\antiwpa.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>ANTIWPA.DLL</b><br />
Default location: %SysDir%\antiwpa.dll</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>ANTIWPA.DLL</strong>  is known as:</h3>
<p>Not-a-Virus.HackTool.Wpakill</p>
<h3><strong>ANTIWPA.DLL</strong> hash:</h3>
<ul>
<li>MD5: 98c332990684cd9f113fbd495841c6fa
</div>
<div id="clist">
How to quickly detect <strong>ANTIWPA.DLL</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Temp%\RarSFX0\AntiWPA3.exe
<li>%Temp%\RarSFX0\lisans.exe
<li>%Temp%\RarSFX0\wgafix.exe
<li>%Temp%\RarSFX1\AMD64\antiwpa.dll
<li>%Temp%\RarSFX1\AntiWPA3.cmd
<li>%Temp%\RarSFX1\IA64\antiwpa.dll
<li>%Temp%\RarSFX1\X86\antiwpa.dll
<li>%SysDir%\antiwpa.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/not-a-virus/antiwpa-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12652&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/not-a-virus/antiwpa-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WEB2NET.EXE is Trojan Injector</title>
		<link>http://greatis.com/blog/how-to-remove-malware/web2net-exe-2.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/web2net-exe-2.htm#comments</comments>
		<pubDate>Tue, 15 May 2012 05:52:58 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Injector]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[WEB2NET.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/web2net-exe-2.htm</guid>
		<description><![CDATA[The file WEB2NET.EXE is identified as a virus dropper. The dropper WEB2NET.EXE is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center. The file WEB2NET.EXE loads into the computer memory and tries to connect to the dangerous web site. Usually the WEB2NET.EXE dropper does not infect the [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>WEB2NET.EXE</b> is identified as a virus dropper.<br />
The dropper <b>WEB2NET.EXE</b> is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.<br />
The file <b>WEB2NET.EXE</b> loads into the computer memory and tries to connect to the dangerous web site.<br />
Usually the  <b>WEB2NET.EXE</b> dropper does not infect the files on the computer and does not replicate itself on other computers.<br />
Kill the <b>WEB2NET.EXE</b> process and delete the file <b>WEB2NET.EXE</b>.</p>
<h2>Malware Analysis of WEB2NET.EXE<br />
Full path on a computer: %Appdata%\web2net.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>WEB2NET.EXE</b><br />
Default location: %Appdata%\web2net.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>WEB2NET.EXE</strong>  is known as:</h3>
<p>Trojan.Injector, Trojan.VB</p>
<h3><strong>WEB2NET.EXE</strong> hash:</h3>
<ul>
<li>MD5: b8480bfcfb1d2fe9503463740d386a68
</div>
<div id="clist">
How to quickly detect <strong>WEB2NET.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Login access: &#8220;%Appdata%\web2net.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\web2net.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/web2net-exe-2.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12650&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/web2net-exe-2.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SOGOUPINYINUP.EXE is Trojan QQPass</title>
		<link>http://greatis.com/blog/how-to-remove-malware/sogoupinyinup-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/sogoupinyinup-exe.htm#comments</comments>
		<pubDate>Tue, 15 May 2012 05:02:44 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[QQPass]]></category>
		<category><![CDATA[SOGOUPINYINUP.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/sogoupinyinup-exe.htm</guid>
		<description><![CDATA[The file SOGOUPINYINUP.EXE is malware related. You must delete the file SOGOUPINYINUP.EXE immediately! Delete the file SOGOUPINYINUP.EXE without delay! Kill the process SOGOUPINYINUP.EXE and remove SOGOUPINYINUP.EXE from the Windows startup. Malware Analysis of SOGOUPINYINUP.EXE Full path on a computer: %Program Files%\SogouPinyinUp.exe Detected by UnHackMe: SOGOUPINYINUP.EXE Default location: %Program Files%\SogouPinyinUp.exe Removal Results: Success Number of reboot: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>SOGOUPINYINUP.EXE</b> is malware related.<br />
You must delete the file <b>SOGOUPINYINUP.EXE</b> immediately!<br />
Delete the file <b>SOGOUPINYINUP.EXE</b> without delay!<br />
Kill the process <b>SOGOUPINYINUP.EXE</b> and remove <b>SOGOUPINYINUP.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of SOGOUPINYINUP.EXE<br />
Full path on a computer: %Program Files%\SogouPinyinUp.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>SOGOUPINYINUP.EXE</b><br />
Default location: %Program Files%\SogouPinyinUp.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>SOGOUPINYINUP.EXE</strong>  is known as:</h3>
<p>Trojan.QQPass, Trojan.Agent</p>
<h3><strong>SOGOUPINYINUP.EXE</strong> hash:</h3>
<ul>
<li>MD5: a670ff4997247322200fd925cc78c94f
</div>
<div id="clist">
How to quickly detect <strong>SOGOUPINYINUP.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\IDO Port: &#8220;%Program Files%\SogouPinyinUp.exe&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Program Files%\common
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Program Files%\common\Utility.dll
<li>%Program Files%\SogouPinyinUp.exe
<li>%SysDir%\info.dat
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/sogoupinyinup-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12644&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/sogoupinyinup-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DHNCHINA.EXE is Adware Tencent</title>
		<link>http://greatis.com/blog/adware/dhnchina-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/adware/dhnchina-exe.htm#comments</comments>
		<pubDate>Tue, 15 May 2012 03:35:47 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[DHNCHINA.EXE]]></category>
		<category><![CDATA[Tencent]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/dhnchina-exe.htm</guid>
		<description><![CDATA[We checked some samples of DHNCHINA.EXE and detected the file DHNCHINA.EXE as threat. Remove the DHNCHINA.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of DHNCHINA.EXE Full path on a computer: %SysDir%\dhnchina.exe Detected by UnHackMe: Item Name: dhnchina.exe Author: TENCENT Related File: %SYSDIR%\DHNCHINA.EXE Type: Registry Run Item Name: cdhnchina.exe Author: Unknown Related [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>DHNCHINA.EXE</b>  and detected the file <b>DHNCHINA.EXE</b> as threat.<br />
Remove the <b>DHNCHINA.EXE</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of DHNCHINA.EXE<br />
Full path on a computer: %SysDir%\dhnchina.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: dhnchina.exe<br />
Author: TENCENT<br />
Related File: %SYSDIR%\DHNCHINA.EXE<br />
Type: Registry Run</p>
<p>Item Name: cdhnchina.exe<br />
Author: Unknown<br />
Related File: %SYSDIR%\CDHNCHINA.EXE<br />
Type: Running Processes</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>DHNCHINA.EXE</strong>  is known as:</h3>
<p>Adware.Tencent, Packed.Klone</p>
<h3><strong>DHNCHINA.EXE</strong> hash:</h3>
<ul>
<li>MD5: 8b729637f9e56f679e78fbcf017126bc
</div>
<div id="clist">
How to quickly detect <strong>DHNCHINA.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\dhnchina.exe: &#8220;%SysDir%\dhnchina.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\cdhnchina.dll
<li>%SysDir%\cdhnchina.exe
<li>%SysDir%\dhnchina.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/adware/dhnchina-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12642&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/adware/dhnchina-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SVCCHOSTT.EXE is Worm Nayrabot</title>
		<link>http://greatis.com/blog/worm/svcchostt-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/svcchostt-exe.htm#comments</comments>
		<pubDate>Tue, 15 May 2012 03:22:31 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[Nayrabot]]></category>
		<category><![CDATA[SVCCHOSTT.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/svcchostt-exe.htm</guid>
		<description><![CDATA[The file SVCCHOSTT.EXE is a computer worm. The worm SVCCHOSTT.EXE is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the SVCCHOSTT.EXE problem as soon as possible! Delete the file SVCCHOSTT.EXE from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>SVCCHOSTT.EXE</b> is a computer worm.<br />
The worm <b>SVCCHOSTT.EXE</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>SVCCHOSTT.EXE</b> problem as soon as possible!<br />
Delete the file <b>SVCCHOSTT.EXE</b> from all infected computers in your network.<br />
Set up your network firewall against <b>SVCCHOSTT.EXE</b> intervention.</p>
<h2>Malware Analysis of SVCCHOSTT.EXE<br />
Full path on a computer: %Appdata%\svcchostt.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: svcchostt.exe<br />
Author: Unknown<br />
Related File: %APPDATA%\SVCCHOSTT.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>SVCCHOSTT.EXE</strong>  is known as:</h3>
<p>Worm.Nayrabot, Trojan.Kuluoz, Trojan.Dapato, Trojan.Diple</p>
<h3><strong>SVCCHOSTT.EXE</strong> hash:</h3>
<ul>
<li>MD5: a7da70c07f8daccbc034aab35e58b85f
</div>
<div id="clist">
How to quickly detect <strong>SVCCHOSTT.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\svcchostt.exe: &#8220;&#8221;%Appdata%\svcchostt.exe&#8221;"
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svcchostt.exe: &#8220;&#8221;%Appdata%\svcchostt.exe&#8221;"
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\svcchostt.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/svcchostt-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12640&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/svcchostt-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WINDOWSFILEDK.EXE is Trojan ProxyChanger</title>
		<link>http://greatis.com/blog/how-to-remove-malware/windowsfiledk-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/windowsfiledk-exe.htm#comments</comments>
		<pubDate>Tue, 15 May 2012 02:49:28 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[ProxyChanger]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[WINDOWSFILEDK.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/windowsfiledk-exe.htm</guid>
		<description><![CDATA[We checked up the file WINDOWSFILEDK.EXE and found it hazardous. The file WINDOWSFILEDK.EXE must be deleted from the system immediately. Kill the process WINDOWSFILEDK.EXE and remove WINDOWSFILEDK.EXE from the Windows startup. Malware Analysis of WINDOWSFILEDK.EXE Full path on a computer: %Appdata%\moka\windowsfiledk.exe Detected by UnHackMe: Item Name: windowsfiledk Author: JXhQ Related File: %APPDATA%\MOKA\WINDOWSFILEDK.EXE Type: Registry Run [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>WINDOWSFILEDK.EXE</b> and found it hazardous.<br />
The file <b>WINDOWSFILEDK.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>WINDOWSFILEDK.EXE</b> and remove <b>WINDOWSFILEDK.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of WINDOWSFILEDK.EXE<br />
Full path on a computer: %Appdata%\moka\windowsfiledk.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: windowsfiledk<br />
Author: JXhQ<br />
Related File: %APPDATA%\MOKA\WINDOWSFILEDK.EXE<br />
Type: Registry Run</p>
<p>Item Name: windowsfiledk.exe<br />
Author: JXhQ<br />
Related File: %APPDATA%\MOKA\WINDOWSFILEDK.EXE<br />
Type: Running Processes</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>WINDOWSFILEDK.EXE</strong>  is known as:</h3>
<p>Trojan.ProxyChanger, Trojan.Injector, Virus.VBInje</p>
<h3><strong>WINDOWSFILEDK.EXE</strong> hash:</h3>
<ul>
<li>MD5: 8627d1b4e5799c5f77952fbdc8f27395
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>WINDOWSFILEDK.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\windowsfiledk: &#8220;%Appdata%\moka\windowsfiledk.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\moka\windowsfiledk.exe
<li>%Temp%\19768.dmp
<li>%Temp%\87dc_appcompat.txt
<li>%Temp%\8A00.dmp
<li>%Temp%\8f04_appcompat.txt
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/windowsfiledk-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12638&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/windowsfiledk-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DNSHELPER.DLL is Backdoor BlackHawk</title>
		<link>http://greatis.com/blog/backdoor/dnshelper-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/dnshelper-dll.htm#comments</comments>
		<pubDate>Mon, 14 May 2012 03:13:05 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[BlackHawk]]></category>
		<category><![CDATA[DNSHELPER.DLL]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/dnshelper-dll.htm</guid>
		<description><![CDATA[The program DNSHELPER.DLL is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with DNSHELPER.DLL. Download for free: http://www.unhackme.com Malware Analysis of DNSHELPER.DLL Full path on a computer: %SysDir%\dnsHelper.DLL Detected by UnHackMe: Item Name: dnsHelper Author: Unknown Related File: %SYSDIR%\DNSHELPER.DLL Type: Svchost DLLs [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>DNSHELPER.DLL</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>DNSHELPER.DLL</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of DNSHELPER.DLL<br />
Full path on a computer: %SysDir%\dnsHelper.DLL</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: dnsHelper<br />
Author: Unknown<br />
Related File: %SYSDIR%\DNSHELPER.DLL<br />
Type: Svchost DLLs</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>DNSHELPER.DLL</strong>  is known as:</h3>
<p>Backdoor.BlackHawk</p>
<h3><strong>DNSHELPER.DLL</strong> hash:</h3>
<ul>
<li>MD5: cf077b679d26e52dba706682e5a9060e
</div>
<div id="clist">The file tries to connect to the dangerous web site.</div>
<div id="clist">
How to quickly detect <strong>DNSHELPER.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_DNSHELPER\0000\Service: &#8220;dnsHelper&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_DNSHELPER\0000\DeviceDesc: &#8220;Smart Card dnsHelper&#8221;
<li>HKLM\System\CurrentControlSet\Services\dnsHelper\Parameters\ServiceDll: &#8220;%SysDir%\dnsHelper.DLL&#8221;
<li>HKLM\System\CurrentControlSet\Services\dnsHelper\DisplayName: &#8220;Smart Card dnsHelper&#8221;
<li>HKLM\System\CurrentControlSet\Services\dnsHelper\Description: &#8220;Management of this computer to take on the smart card read dnsHelper&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\dnsHelper.DLL
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/dnshelper-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12636&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/dnshelper-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ITUNES_SERVICE01.EXE is Trojan RansomGimemo</title>
		<link>http://greatis.com/blog/how-to-remove-malware/itunes_service01-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/itunes_service01-exe.htm#comments</comments>
		<pubDate>Sun, 13 May 2012 03:33:31 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[ITUNES_SERVICE01.EXE]]></category>
		<category><![CDATA[RansomGimemo]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/itunes_service01-exe.htm</guid>
		<description><![CDATA[Ransom Screen Locker ITUNES_SERVICE01.EXE is a malicious program. ITUNES_SERVICE01.EXE blocks user access to a computer that it infects. ITUNES_SERVICE01.EXE demands a ransom paid for unlocking the computer. Malware Analysis of ITUNES_SERVICE01.EXE Full path on a computer: %Appdata%\itunes_service01.exe Detected by RegRun Warrior: Item Name: shell Author: Unknown Related File: %Appdata%\itunes_service01.exe Type: System.ini Item Name: UserInit Author: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Ransom Screen Locker <strong>ITUNES_SERVICE01.EXE</strong> is a malicious program. <strong>ITUNES_SERVICE01.EXE</strong> blocks user access to a computer that it infects.  <strong>ITUNES_SERVICE01.EXE</strong> demands a ransom paid for unlocking the computer.</p>
<h2>Malware Analysis of ITUNES_SERVICE01.EXE<br />
Full path on a computer: %Appdata%\itunes_service01.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p>Item Name: shell<br />
Author: Unknown<br />
Related File: %Appdata%\itunes_service01.exe<br />
Type: System.ini</p>
<p>Item Name: UserInit<br />
Author: Unknown<br />
Related File: %Appdata%\itunes_service01.exe,%WinDir%\System32\userinit.exe,<br />
Type: UserInit Value</p>
<p>Item Name: d31ybB8YFv9cUxg<br />
Author: Unknown<br />
Related File: %APPDATA%\ITUNES_SERVICE01.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>ITUNES_SERVICE01.EXE</strong>  is known as:</h3>
<p>Trojan.RansomGimemo, Trojan.LockScreen</p>
<h3><strong>ITUNES_SERVICE01.EXE</strong> hash:</h3>
<ul>
<li>MD5: fd3f7aaef6b290ac4c1d6ebcb36209c9
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>ITUNES_SERVICE01.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\d31ybB8YFv9cUxg: &#8220;%Appdata%\itunes_service01.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\d31ybB8YFv9cUxg: &#8220;%Appdata%\itunes_service01.exe&#8221;
<li>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: &#8220;%Appdata%\itunes_service01.exe&#8221;
<li>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: &#8220;%Appdata%\itunes_service01.exe,%WinDir%\System32\userinit.exe,&#8221;
<li>HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: &#8220;%Appdata%\itunes_service01.exe&#8221;
<li>HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: &#8220;%Appdata%\itunes_service01.exe,%WinDir%\System32\userinit.exe,&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\itunes_service01.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/itunes_service01-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12634&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/itunes_service01-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>68Y0EOY0LT.EXE is Dropper Dapato</title>
		<link>http://greatis.com/blog/how-to-remove-malware/68y0eoy0lt-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/68y0eoy0lt-exe.htm#comments</comments>
		<pubDate>Sat, 12 May 2012 03:08:32 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[68Y0EOY0LT.EXE]]></category>
		<category><![CDATA[Dapato]]></category>
		<category><![CDATA[Dropper]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/68y0eoy0lt-exe.htm</guid>
		<description><![CDATA[The program 68Y0EOY0LT.EXE is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with 68Y0EOY0LT.EXE. Download for free: http://www.unhackme.com Malware Analysis of 68Y0EOY0LT.EXE Full path on a computer: %Appdata%\68Y0EOY0LT.exe Detected by UnHackMe: 68Y0EOY0LT.EXE Default location: %Appdata%\68Y0EOY0LT.exe Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>68Y0EOY0LT.EXE</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>68Y0EOY0LT.EXE</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of 68Y0EOY0LT.EXE<br />
Full path on a computer: %Appdata%\68Y0EOY0LT.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>68Y0EOY0LT.EXE</b><br />
Default location: %Appdata%\68Y0EOY0LT.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>68Y0EOY0LT.EXE</strong>  is known as:</h3>
<p>Dropper.Dapato, Virus.ILCrypt, Backdoor.Blackshades, Worm.Ainslot</p>
<h3><strong>68Y0EOY0LT.EXE</strong> hash:</h3>
<ul>
<li>MD5: 49c64108587681117d9db258514b4fa8
</div>
<div id="clist">
How to quickly detect <strong>68Y0EOY0LT.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Defender: &#8220;%Appdata%\WinDefender\windefender.exe&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows: &#8220;%Appdata%\Windows\windows.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\68Y0EOY0LT.exe
<li>%Appdata%\svchost
<li>%Appdata%\WinDefender\windefender.exe
<li>%Appdata%\Windows\windows.exe
<li>%Temp%\chrome.exe
<li>%Temp%\svchost.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/68y0eoy0lt-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12632&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/68y0eoy0lt-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SOUNDVOL32.EXE is Trojan Sdbot</title>
		<link>http://greatis.com/blog/how-to-remove-malware/soundvol32-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/soundvol32-exe.htm#comments</comments>
		<pubDate>Fri, 11 May 2012 04:06:53 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[SdBot]]></category>
		<category><![CDATA[SOUNDVOL32.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/soundvol32-exe.htm</guid>
		<description><![CDATA[We checked up the file SOUNDVOL32.EXE and found it hazardous. The file SOUNDVOL32.EXE must be deleted from the system immediately. Kill the process SOUNDVOL32.EXE and remove SOUNDVOL32.EXE from the Windows startup. Malware Analysis of SOUNDVOL32.EXE Full path on a computer: %SysDir%\soundvol32.exe Detected by UnHackMe: Item Name: Microsoft Author: Unknown Related File: %SysDir%\SOUNDVOL32.EXE Type: Registry Run [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>SOUNDVOL32.EXE</b> and found it hazardous.<br />
The file <b>SOUNDVOL32.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>SOUNDVOL32.EXE</b> and remove <b>SOUNDVOL32.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of SOUNDVOL32.EXE<br />
Full path on a computer: %SysDir%\soundvol32.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Microsoft<br />
Author: Unknown<br />
Related File: %SysDir%\SOUNDVOL32.EXE<br />
Type: Registry Run</p>
<p>Item Name: soundvol32.exe<br />
Author: Unknown<br />
Related File: %SYSDIR%\SOUNDVOL32.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>SOUNDVOL32.EXE</strong>  is known as:</h3>
<p>Trojan.Sdbot, Trojan.Jorik</p>
<h3><strong>SOUNDVOL32.EXE</strong> hash:</h3>
<ul>
<li>MD5: 2c44fe67124cc9fa68360d42174673b9
</div>
<div id="clist">
How to quickly detect <strong>SOUNDVOL32.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft: &#8220;soundvol32.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft: &#8220;soundvol32.exe&#8221;
<li>HKCU\Software\ASProtect\Microsoft: &#8220;soundvol32.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\soundvol32.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/soundvol32-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12630&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/soundvol32-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CSDRIVE32.EXE is Worm Kolab</title>
		<link>http://greatis.com/blog/worm/csdrive32-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/csdrive32-exe.htm#comments</comments>
		<pubDate>Fri, 11 May 2012 02:55:05 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[CSDRIVE32.EXE]]></category>
		<category><![CDATA[Kolab]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/csdrive32-exe.htm</guid>
		<description><![CDATA[The file CSDRIVE32.EXE is a computer worm. The worm CSDRIVE32.EXE is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the CSDRIVE32.EXE problem as soon as possible! Delete the file CSDRIVE32.EXE from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>CSDRIVE32.EXE</b> is a computer worm.<br />
The worm <b>CSDRIVE32.EXE</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>CSDRIVE32.EXE</b> problem as soon as possible!<br />
Delete the file <b>CSDRIVE32.EXE</b> from all infected computers in your network.<br />
Set up your network firewall against <b>CSDRIVE32.EXE</b> intervention.</p>
<h2>Malware Analysis of CSDRIVE32.EXE<br />
Full path on a computer: %WinDir%\csdrive32.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Microsoft Driver Setup<br />
Author: Unknown<br />
Related File: %WinDir%\CSDRIVE32.EXE<br />
Type: Explorer Run</p>
<p>Item Name: csdrive32.exe<br />
Author: Unknown<br />
Related File: %WinDir%\CSDRIVE32.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>CSDRIVE32.EXE</strong>  is known as:</h3>
<p>Worm.Kolab, Backdoor.Rbot, Worm.Pushbot</p>
<h3><strong>CSDRIVE32.EXE</strong> hash:</h3>
<ul>
<li>MD5: 7f088fba47368255f9e35fada086a86a
</div>
<div id="clist">
How to quickly detect <strong>CSDRIVE32.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Microsoft Driver Setup: &#8220;%WinDir%\csdrive32.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Driver Setup: &#8220;%WinDir%\csdrive32.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\csdrive32.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/csdrive32-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12628&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/csdrive32-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ARTEENBARCELONA2.DLL is Adware MSNAgent</title>
		<link>http://greatis.com/blog/adware/arteenbarcelona2-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/adware/arteenbarcelona2-dll.htm#comments</comments>
		<pubDate>Thu, 10 May 2012 06:19:45 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[ARTEENBARCELONA2.DLL]]></category>
		<category><![CDATA[MSNAgent]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/arteenbarcelona2-dll.htm</guid>
		<description><![CDATA[We received the file ARTEENBARCELONA2.DLL and detected that ARTEENBARCELONA2.DLL is not good. ARTEENBARCELONA2.DLL is Adware. You should remove the file ARTEENBARCELONA2.DLL. Kill the process ARTEENBARCELONA2.DLL and remove ARTEENBARCELONA2.DLL from Windows. Malware Analysis of ARTEENBARCELONA2.DLL Full path on a computer: %Program Files%\www.arteenbarcelona.com\arteenbarcelona2.dll Detected by UnHackMe: Item Name: {4B976F76-B0BC-4db6-BC34-121A7C9D4A28} Author: IE Toolbar Related File: C:\PROGRA~1\WWWART~1.COM\ARTEEN~1.DLL Type: Browser [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We received the file <b>ARTEENBARCELONA2.DLL</b> and detected that <b>ARTEENBARCELONA2.DLL</b> is not good.<br />
<b>ARTEENBARCELONA2.DLL</b> is Adware. You should remove the file <b>ARTEENBARCELONA2.DLL</b>.<br />
Kill the process <b>ARTEENBARCELONA2.DLL</b> and remove <b>ARTEENBARCELONA2.DLL</b> from Windows.</p>
<h2>Malware Analysis of ARTEENBARCELONA2.DLL<br />
Full path on a computer: %Program Files%\www.arteenbarcelona.com\arteenbarcelona2.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: {4B976F76-B0BC-4db6-BC34-121A7C9D4A28}<br />
Author: IE Toolbar<br />
Related File: C:\PROGRA~1\WWWART~1.COM\ARTEEN~1.DLL<br />
Type: Browser Helper Objects</p>
<p>Item Name: {25F97EB4-1C02-45BA-BA0C-E67AACE64D4A}<br />
Author:<br />
Related File: %PROGRAM FILES%\WWW.ARTEENBARCELONA.COM\ARTEENBARCELONA2.DLL<br />
Type: Toolbars</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>ARTEENBARCELONA2.DLL</strong>  is known as:</h3>
<p>Adware.MSNAgent, Adware.Istbar, Adware.Toolbar.Eztracks, Adware.Mostofate, Adware.Softomate</p>
<h3><strong>ARTEENBARCELONA2.DLL</strong> hash:</h3>
<ul>
<li>MD5: eeb02caf9fabd673443c42e8bcc4ca8b
</div>
<div id="clist">The file tries to connect to the dangerous web site.</div>
<div id="clist">
How to quickly detect <strong>ARTEENBARCELONA2.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Classes\CLSID\{25F97EB4-1C02-45BA-BA0C-E67AACE64D4A}\InprocServer32\: &#8220;%Program Files%\www.arteenbarcelona.com\arteenbarcelona2.dll&#8221;
<li>HKLM\Software\Classes\CLSID\{4B976F76-B0BC-4db6-BC34-121A7C9D4A28}\InprocServer32\: &#8220;C:\PROGRA~1\WWWART~1.COM\ARTEEN~1.DLL&#8221;
<li>HKLM\Software\Classes\TypeLib\{B9DDDDA0-87DF-4003-9D7C-84B0765CEF76}\1.0\0\win32\: &#8220;%Program Files%\www.arteenbarcelona.com\arteenbarcelona2.dll&#8221;
<li>HKLM\Software\Classes\TypeLib\{B9DDDDA0-87DF-4003-9D7C-84B0765CEF76}\1.0\HELPDIR\: &#8220;%Program Files%\www.arteenbarcelona.com\&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Program Files%\www.arteenbarcelona.com
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Program Files%\www.arteenbarcelona.com\arteenbarcelona.bmp
<li>%Program Files%\www.arteenbarcelona.com\arteenbarcelona2.crc
<li>%Program Files%\www.arteenbarcelona.com\arteenbarcelona2.dll
<li>%Program Files%\www.arteenbarcelona.com\basis.xml
<li>%Program Files%\www.arteenbarcelona.com\error.html
<li>%Program Files%\www.arteenbarcelona.com\icons.bmp
<li>%Program Files%\www.arteenbarcelona.com\msvcp60.dll
<li>%Program Files%\www.arteenbarcelona.com\msvcrt.dll
<li>%Program Files%\www.arteenbarcelona.com\options.html
<li>%Program Files%\www.arteenbarcelona.com\version.txt
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/adware/arteenbarcelona2-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12626&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/adware/arteenbarcelona2-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSJK8S.EXE is Virus Virut</title>
		<link>http://greatis.com/blog/virus/osjk8s-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/virus/osjk8s-exe.htm#comments</comments>
		<pubDate>Thu, 10 May 2012 05:42:01 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[OSJK8S.EXE]]></category>
		<category><![CDATA[Virut]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/osjk8s-exe.htm</guid>
		<description><![CDATA[We checked up the file OSJK8S.EXE and found it hazardous. The file OSJK8S.EXE must be deleted from the system immediately. Kill the process OSJK8S.EXE and remove OSJK8S.EXE from the Windows startup. Malware Analysis of OSJK8S.EXE Full path on a computer: %Appdata%\osjk8s.exe Detected by UnHackMe: Item Name: NWCWorkstation Author: Microsoft Corporation Related File: %SYSDIR%\NWCWKS.DLL Type: Svchost [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>OSJK8S.EXE</b> and found it hazardous.<br />
The file <b>OSJK8S.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>OSJK8S.EXE</b> and remove <b>OSJK8S.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of OSJK8S.EXE<br />
Full path on a computer: %Appdata%\osjk8s.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: NWCWorkstation<br />
Author: Microsoft Corporation<br />
Related File: %SYSDIR%\NWCWKS.DLL<br />
Type: Svchost DLLs</p>
<p>Item Name: MouseDriver<br />
Author:<br />
Related File: %Appdata%\MouseDriver.bat<br />
Type: Auto Services</p>
<p>Item Name: aqjunayn<br />
Author: YthqO<br />
Related File: %SYSDIR%\AQJUNAYN.EXE<br />
Type: Registry Run</p>
<p>Item Name: Regedit32<br />
Author:<br />
Related File: %SysDir%\regedit.exe<br />
Type: Registry Run</p>
<p>Item Name: aqjunayn.exe<br />
Author: YthqO<br />
Related File: %PROFILE%\AQJUNAYN.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<p>Item Name: tcpudp<br />
Author: Unknown<br />
Related File: %WinDir%\BN6.TMP<br />
Type: Registry Run</p>
<p>Item Name: osjk8s<br />
Author:<br />
Related File: %APPDATA%\OSJK8S.EXE<br />
Type: Registry Run</p>
<p>Item Name: l3yg2h61ay<br />
Author: Unknown<br />
Related File: C:\DOCUMENTS AND SETTINGS\ALL USERS\L3YG2H61AY.EXE<br />
Type: Registry Run</p>
<p>Item Name: osjk8s.exe<br />
Author:<br />
Related File: %APPDATA%\OSJK8S.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<p>Item Name: l3yg2h61ay.exe<br />
Author: Unknown<br />
Related File: C:\DOCUMENTS AND SETTINGS\ALL USERS\L3YG2H61AY.EXE<br />
Type: Running Processes</p>
<p>Item Name: BN6.tmp<br />
Author: Unknown<br />
Related File: %TEMP%\BN6.TMP<br />
Type: Running Processes</p>
<p>Item Name: VRT5.tmp<br />
Author: Unknown<br />
Related File: %WinDir%\TEMP\VRT5.TMP<br />
Type: Running Processes</p>
<h3>After first reboot detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Rootkit: NECURS<br />
Author: Unknown<br />
Related File:<br />
Type: Devices in Memory</p>
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p>Item Name: MouseDriver<br />
Author:<br />
Related File: %APPDATA%\MOUSEDRIVER.BAT<br />
Type: Drivers</p>
<p>Item Name: 4d067d35f313de7<br />
Author:<br />
Related File: %SYSDIR%\DRIVERS\4D067D35F313DE7.SYS<br />
Type: Drivers</p>
<p>Item Name: 5cf2180pgz<br />
Author: Unknown<br />
Related File: C:\DOCUMENTS AND SETTINGS\ALL USERS\5CF2180PGZ.EXE<br />
Type: Registry Run</p>
<p>Item Name: osjk8s<br />
Author:<br />
Related File: %APPDATA%\OSJK8S.EXE<br />
Type: Registry Run</p>
<p>Item Name: l3yg2h61ay<br />
Author: Unknown<br />
Related File: %PROFILE%\L3YG2H61AY.EXE<br />
Type: Registry Run</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>OSJK8S.EXE</strong>  is known as:</h3>
<p>Virus.Virut</p>
<h3><strong>OSJK8S.EXE</strong> hash:</h3>
<ul>
<li>MD5: 672e6894ded72ced69fc8a8a0f48f835
</div>
<div id="clist">The file tries to connect to the dangerous web site.</div>
<div id="clist">
How to quickly detect <strong>OSJK8S.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\aqjunayn: &#8220;%WinDir%\System32\aqjunayn.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\osjk8s: &#8220;%Appdata%\osjk8s.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\l3yg2h61ay: &#8220;C:\Documents and Settings\All Users\l3yg2h61ay.exe&#8221;
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Regedit32: &#8220;%SysDir%\regedit.exe&#8221;
<li>HKLM\Software\tgs90gv74r\tgs90gv74rexepath: &#8220;%Appdata%\osjk8s.exe&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_MOUSEDRIVER\0000\Service: &#8220;MouseDriver&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_MOUSEDRIVER\0000\DeviceDesc: &#8220;MouseDriver&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_NWCWORKSTATION\0000\Service: &#8220;NWCWorkstation&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_NWCWORKSTATION\0000\DeviceDesc: &#8220;Client Service for NetWare&#8221;
<li>HKLM\System\CurrentControlSet\Services\MouseDriver\ImagePath: &#8220;%Appdata%\MouseDriver.bat&#8221;
<li>HKLM\System\CurrentControlSet\Services\MouseDriver\DisplayName: &#8220;MouseDriver&#8221;
<li>HKLM\System\CurrentControlSet\Services\NWCWorkstation\Parameters\ServiceDll: &#8220;%SystemRoot%\system32\nwcwks.dll&#8221;
<li>HKLM\System\CurrentControlSet\Services\NWCWorkstation\DisplayName: &#8220;Client Service for NetWare&#8221;
<li>HKLM\System\CurrentControlSet\Services\NWCWorkstation\Description: &#8220;Provides access to file and print resources on NetWare networks.&#8221;
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\tcpudp: &#8220;%WinDir%\BN5.tmp&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%\MouseDriver.bat
<li>%Appdata%\osjk8s.exe
<li>%Appdata%\osjk8s.log
<li>%Temp%\BN5.tmp
<li>%Profile%\aqjunayn.exe
<li>C:\Documents and Settings\All Users\l3yg2h61ay.exe
<li>%SysDir%\aqjunayn.exe
<li>%SysDir%\nwcwks.dll
<li>%WinDir%\Temp\VRT1.tmp
<li>%WinDir%\Temp\VRT2.tmp
<li>%WinDir%\Temp\VRT3.tmp
<li>%WinDir%\Temp\VRT4.tmp
<li>%WinDir%\Temp\VRT6.tmp
<li>%WinDir%\BN5.tmp
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/virus/osjk8s-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12624&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/virus/osjk8s-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SVCGHOST.EXE is Backdoor Umbra</title>
		<link>http://greatis.com/blog/backdoor/svcghost-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/svcghost-exe.htm#comments</comments>
		<pubDate>Thu, 10 May 2012 03:40:49 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[SVCGHOST.EXE]]></category>
		<category><![CDATA[Umbra]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/svcghost-exe.htm</guid>
		<description><![CDATA[The program SVCGHOST.EXE is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with SVCGHOST.EXE. Download for free: http://www.unhackme.com Malware Analysis of SVCGHOST.EXE Full path on a computer: %WinDir%\svcghost.exe Detected by UnHackMe: Item Name: Windows Updater Author: Unknown Related File: %WinDir%\SVCGHOST.EXE Type: Registry [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>SVCGHOST.EXE</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>SVCGHOST.EXE</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of SVCGHOST.EXE<br />
Full path on a computer: %WinDir%\svcghost.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: Windows Updater<br />
Author: Unknown<br />
Related File: %WinDir%\SVCGHOST.EXE<br />
Type: Registry Run</p>
<p>Item Name: svcghost.exe<br />
Author: Unknown<br />
Related File: %WinDir%\SVCGHOST.EXE<br />
Type: Running Processes</p>
<p><b>SVCGHOST.EXE</b><br />
Default location: %WinDir%\svcghost.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>SVCGHOST.EXE</strong>  is known as:</h3>
<p>Backdoor.Umbra, Trojan.Dapato, Trojan.Malex</p>
<h3><strong>SVCGHOST.EXE</strong> hash:</h3>
<ul>
<li>MD5: 9b29acb54e0b4e4a7adbb5d3801f895f
</div>
<div id="clist">
How to quickly detect <strong>SVCGHOST.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Updater: &#8220;&#8221;%WinDir%\svcghost.exe&#8221;"
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WinDir%\svcghost.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/svcghost-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12622&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/svcghost-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FINDLOCK.DLL is Trojan ATRAPS</title>
		<link>http://greatis.com/blog/how-to-remove-malware/findlock-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/findlock-dll.htm#comments</comments>
		<pubDate>Wed, 09 May 2012 03:50:48 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[ATRAPS]]></category>
		<category><![CDATA[FINDLOCK.DLL]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/findlock-dll.htm</guid>
		<description><![CDATA[We checked some samples of FINDLOCK.DLL and detected the file FINDLOCK.DLL as threat. Remove the FINDLOCK.DLL file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of FINDLOCK.DLL Full path on a computer: %Appdata%FindLockfindlock.dll Detected by UnHackMe: FINDLOCK.DLL Default location: %Appdata%FindLockfindlock.dll Removal Results: Success Number of reboot: 1 FINDLOCK.DLL is known as: Trojan.ATRAPS, SecurityRisk.Downldr [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>FINDLOCK.DLL</b>  and detected the file <b>FINDLOCK.DLL</b> as threat.<br />
Remove the <b>FINDLOCK.DLL</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of FINDLOCK.DLL<br />
Full path on a computer: %Appdata%FindLockfindlock.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>FINDLOCK.DLL</b><br />
Default location: %Appdata%FindLockfindlock.dll</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>FINDLOCK.DLL</strong>  is known as:</h3>
<p>Trojan.ATRAPS, SecurityRisk.Downldr</p>
<h3><strong>FINDLOCK.DLL</strong> hash:</h3>
<ul>
<li>MD5: 8ee9fc48d2c868e1b72f3924df2b6017
</div>
<div id="clist">The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.</div>
<div id="clist">
How to quickly detect <strong>FINDLOCK.DLL</strong> presence?</p>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Appdata%FindLock
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%FindLockfindlock.dll
<li>%Appdata%FindLockfl_dn.exe
<li>%Appdata%FindLockfl_install.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/findlock-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12596&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/findlock-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WINOWIS.DLL is Backdoor Delf</title>
		<link>http://greatis.com/blog/backdoor/winowis-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/backdoor/winowis-dll.htm#comments</comments>
		<pubDate>Wed, 09 May 2012 03:30:58 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[Delf]]></category>
		<category><![CDATA[WINOWIS.DLL]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/winowis-dll.htm</guid>
		<description><![CDATA[The program WINOWIS.DLL is used for hidden penetration into PC and its remote administration. UnHackMe is recommended as a reliable program for solving the problem with WINOWIS.DLL. Download for free: http://www.unhackme.com Malware Analysis of WINOWIS.DLL Full path on a computer: %SysDir%winowis.dll Detected by UnHackMe: Item Name: windows user Author: Unknown Related File: %SYSDIR%WINOWIS.DLL Type: Svchost [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The program <b>WINOWIS.DLL</b> is used for hidden penetration into PC and its remote administration.<br />
UnHackMe is recommended as a reliable program for solving the problem with <b>WINOWIS.DLL</b>.<br />
Download for free: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of WINOWIS.DLL<br />
Full path on a computer: %SysDir%winowis.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: windows user<br />
Author: Unknown<br />
Related File: %SYSDIR%WINOWIS.DLL<br />
Type: Svchost DLLs</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>WINOWIS.DLL</strong>  is known as:</h3>
<p>Backdoor.Delf, Backdoor.Graybird, BackDoor.Pigeon</p>
<h3><strong>WINOWIS.DLL</strong> hash:</h3>
<ul>
<li>MD5: 16b8700dcb051034f062668365b8533c
</div>
<div id="clist">The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.</div>
<div id="clist">
How to quickly detect <strong>WINOWIS.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLMSystemCurrentControlSetEnumRootLEGACY_WINDOWS_USER 000Service: &#8220;windows user&#8221;
<li>HKLMSystemCurrentControlSetEnumRootLEGACY_WINDOWS_USER 000DeviceDesc: &#8220;windows user&#8221;
<li>HKLMSystemCurrentControlSetServiceswindows userParametersServiceDll: &#8220;%SysDir%winowis.dll&#8221;
<li>HKLMSystemCurrentControlSetServiceswindows userDisplayName: &#8220;windows user&#8221;
<li>HKLMSystemCurrentControlSetServiceswindows userDescription: &#8220;windows user&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%winowis.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/backdoor/winowis-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12558&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/backdoor/winowis-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MSDCSC.EXE is Trojan Agent</title>
		<link>http://greatis.com/blog/how-to-remove-malware/msdcsc-exe-3.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/msdcsc-exe-3.htm#comments</comments>
		<pubDate>Wed, 09 May 2012 03:29:05 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Agent]]></category>
		<category><![CDATA[MSDCSC.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/msdcsc-exe-3.htm</guid>
		<description><![CDATA[The file MSDCSC.EXE is malware related. You must delete the file MSDCSC.EXE immediately! Delete the file MSDCSC.EXE without delay! Kill the process MSDCSC.EXE and remove MSDCSC.EXE from the Windows startup. Malware Analysis of MSDCSC.EXE Full path on a computer: C:MSDCSCmsdcsc.exe Detected by UnHackMe: MSDCSC.EXE Default location: C:MSDCSCmsdcsc.exe Removal Results: Success Number of reboot: 1 MSDCSC.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>MSDCSC.EXE</b> is malware related.<br />
You must delete the file <b>MSDCSC.EXE</b> immediately!<br />
Delete the file <b>MSDCSC.EXE</b> without delay!<br />
Kill the process <b>MSDCSC.EXE</b> and remove <b>MSDCSC.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of MSDCSC.EXE<br />
Full path on a computer: C:MSDCSCmsdcsc.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>MSDCSC.EXE</b><br />
Default location: C:MSDCSCmsdcsc.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>MSDCSC.EXE</strong>  is known as:</h3>
<p>Trojan.Agent, Trojan.Injector, Backdoor.Fynloski</p>
<h3><strong>MSDCSC.EXE</strong> hash:</h3>
<ul>
<li>MD5: 8c82de32ab2b407451b9fc054c09f717
</div>
<div id="clist">The file tries to connect to the dangerous web site.</div>
<div id="clist">
How to quickly detect <strong>MSDCSC.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCUSoftwareMicrosoftWindowsCurrentVersionRunMicroUpdate: &#8220;C:MSDCSCmsdcsc.exe&#8221;
<li>HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonUserinit: &#8220;%SysDir%userinit.exe,C:MSDCSCmsdcsc.exe&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Appdata%dclogs
<li>C:MSDCSC
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>C:MSDCSCmsdcsc.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/msdcsc-exe-3.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12594&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/msdcsc-exe-3.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MODDEDMAPAIO.EXE is Trojan Injector</title>
		<link>http://greatis.com/blog/how-to-remove-malware/moddedmapaio-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/moddedmapaio-exe.htm#comments</comments>
		<pubDate>Wed, 09 May 2012 03:27:49 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Injector]]></category>
		<category><![CDATA[MODDEDMAPAIO.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/moddedmapaio-exe.htm</guid>
		<description><![CDATA[The file MODDEDMAPAIO.EXE is malware related. You must delete the file MODDEDMAPAIO.EXE immediately! Delete the file MODDEDMAPAIO.EXE without delay! Kill the process MODDEDMAPAIO.EXE and remove MODDEDMAPAIO.EXE from the Windows startup. Malware Analysis of MODDEDMAPAIO.EXE Full path on a computer: %Appdata%ModdedMapAIO.exe Detected by UnHackMe: MODDEDMAPAIO.EXE Default location: %Appdata%ModdedMapAIO.exe Removal Results: Success Number of reboot: 1 MODDEDMAPAIO.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>MODDEDMAPAIO.EXE</b> is malware related.<br />
You must delete the file <b>MODDEDMAPAIO.EXE</b> immediately!<br />
Delete the file <b>MODDEDMAPAIO.EXE</b> without delay!<br />
Kill the process <b>MODDEDMAPAIO.EXE</b> and remove <b>MODDEDMAPAIO.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of MODDEDMAPAIO.EXE<br />
Full path on a computer: %Appdata%ModdedMapAIO.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>MODDEDMAPAIO.EXE</b><br />
Default location: %Appdata%ModdedMapAIO.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>MODDEDMAPAIO.EXE</strong>  is known as:</h3>
<p>Trojan.Injector, Trojan.Dapato</p>
<h3><strong>MODDEDMAPAIO.EXE</strong> hash:</h3>
<ul>
<li>MD5: d5ac40362376abbccedba6a1919913d4
</div>
<div id="clist">The file tries to download information from some web sites.</div>
<div id="clist">
How to quickly detect <strong>MODDEDMAPAIO.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCUSoftwareMicrosoftWindowsCurrentVersionRunJava Enviroment: &#8220;%Appdata%ModdedMapAIO.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%Keylog
<li>%Appdata%KGAPBSMQCO.exe
<li>%Appdata%ModdedMapAIO.exe
<li>%Appdata%XOmDQ.txt
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/moddedmapaio-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12598&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/moddedmapaio-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GUAJI27.EXE is Trojan Clons</title>
		<link>http://greatis.com/blog/how-to-remove-malware/guaji27-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/guaji27-exe.htm#comments</comments>
		<pubDate>Wed, 09 May 2012 03:24:48 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Clons]]></category>
		<category><![CDATA[GUAJI27.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/guaji27-exe.htm</guid>
		<description><![CDATA[Is the file GUAJI27.EXE located on your computer? Then your computer is infected. We do suggest you should remove GUAJI27.EXE from your computer as soon as possible. GUAJI27.EXE is Trojan/Backdoor. Kill the process GUAJI27.EXE and remove GUAJI27.EXE from the Windows startup. Malware Analysis of GUAJI27.EXE Full path on a computer: GuaJi27.exe Detected by UnHackMe: GUAJI27.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Is the file <b>GUAJI27.EXE</b> located on your computer? Then your computer is infected.<br />
We do suggest you should remove <b>GUAJI27.EXE</b> from your computer as soon as possible.<br />
<b>GUAJI27.EXE</b> is Trojan/Backdoor.<br />
Kill the process <b>GUAJI27.EXE</b> and remove <b>GUAJI27.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of GUAJI27.EXE<br />
Full path on a computer: GuaJi27.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>GUAJI27.EXE</b><br />
Default location: %Temp%GuaJi27.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>GUAJI27.EXE</strong>  is known as:</h3>
<p>Trojan.Clons, Trojan.MulDrop2, Trojan.Bumat</p>
<h3><strong>GUAJI27.EXE</strong> hash:</h3>
<ul>
<li>MD5: c04db7f5ca47ad017cf9b019cae57ded
</div>
<div id="clist">The file tries to connect to the dangerous web site.</div>
<div id="clist">
How to quickly detect <strong>GUAJI27.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLMSoftwareMicrosoftWindowsCurrentVersionRunDDGuaJi: &#8220;%Temp%GuaJi27.exe /tray&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Temp%143562cds.rar
<li>%Temp%202656draw.jpg
<li>%Temp%GuaJi27.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/guaji27-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12592&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/guaji27-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>THOR-BATISTA-ATROPELA-HOMEM.EXE is Trojan Banker</title>
		<link>http://greatis.com/blog/how-to-remove-malware/thor-batista-atropela-homem-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/thor-batista-atropela-homem-exe.htm#comments</comments>
		<pubDate>Wed, 09 May 2012 03:14:51 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Banker]]></category>
		<category><![CDATA[THOR-BATISTA-ATROPELA-HOMEM.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/thor-batista-atropela-homem-exe.htm</guid>
		<description><![CDATA[The file THOR-BATISTA-ATROPELA-HOMEM.EXE is identified as the Trojan Program that is used for stealing bank information and users passwords. To delete THOR-BATISTA-ATROPELA-HOMEM.EXE we suggest you should use UnHackMe: http://www.unhackme.com Malware Analysis of THOR-BATISTA-ATROPELA-HOMEM.EXE Full path on a computer: %Appdata%Thor-Batista-atropela-homem.exe Detected by UnHackMe: Item Name: sbthost Author: Microsoft Related File: %APPDATA%THOR-BATISTA-ATROPELA-HOMEM.EXE Type: Registry Run Item Name: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>THOR-BATISTA-ATROPELA-HOMEM.EXE</b>  is identified as the Trojan Program that is used for stealing bank information and  users passwords.<br />
To delete  <b>THOR-BATISTA-ATROPELA-HOMEM.EXE</b>  we suggest you should use UnHackMe:<br />
<a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of THOR-BATISTA-ATROPELA-HOMEM.EXE<br />
Full path on a computer: %Appdata%Thor-Batista-atropela-homem.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p>Item Name: sbthost<br />
Author: Microsoft<br />
Related File: %APPDATA%THOR-BATISTA-ATROPELA-HOMEM.EXE<br />
Type: Registry Run</p>
<p>Item Name: Thor-Batista-atropela-homem.exe<br />
Author:<br />
Related File: %APPDATA%THOR-BATISTA-ATROPELA-HOMEM.EXE<br />
Type: Detected using Heuristic Algorithm</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>THOR-BATISTA-ATROPELA-HOMEM.EXE</strong>  is known as:</h3>
<p>Trojan.Banker, Trojan.ProxyChanger</p>
<h3><strong>THOR-BATISTA-ATROPELA-HOMEM.EXE</strong> hash:</h3>
<ul>
<li>MD5: 4fb71080eb11325b31ef006dd3108e35
</div>
<div id="clist">The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.</div>
<div id="clist">
How to quickly detect <strong>THOR-BATISTA-ATROPELA-HOMEM.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKCUSoftwareMicrosoftWindowsCurrentVersionInternet SettingsAutoConfigURL: &#8220;http://187.109.161.34/index1.php&#8221;
<li>HKCUSoftwareMicrosoftWindowsCurrentVersionRunsbthost: &#8220;%Appdata%Thor-Batista-atropela-homem.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Appdata%tem.txt
<li>%Appdata%Thor-Batista-atropela-homem.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/thor-batista-atropela-homem-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12578&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/thor-batista-atropela-homem-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICAM5USB.DLL is Rootkit ZeroAccess</title>
		<link>http://greatis.com/blog/rootkit/icam5usb-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/rootkit/icam5usb-dll.htm#comments</comments>
		<pubDate>Tue, 08 May 2012 14:29:09 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[ICAM5USB.DLL]]></category>
		<category><![CDATA[ZeroAccess]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/icam5usb-dll.htm</guid>
		<description><![CDATA[Rootkit ICAM5USB.DLL is software that enables continued privileged access to a computer while actively hiding its presence. Detection and removal of ICAM5USB.DLL may be a very difficult process. You should use anti-rootkit software to fix the ICAM5USB.DLL problem. Malware Analysis of ICAM5USB.DLL Full path on a computer: %SysDir%\ICAM5USB.dll Detected by RegRun Warrior: ICAM5USB.DLL Default location: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Rootkit <b>ICAM5USB.DLL</b> is software that enables continued privileged access to a computer while actively hiding its presence.<br />
Detection and removal of <b>ICAM5USB.DLL</b> may be a very difficult process.<br />
You should  use anti-rootkit software to fix the <b>ICAM5USB.DLL</b> problem.</p>
<h2>Malware Analysis of ICAM5USB.DLL<br />
Full path on a computer: %SysDir%\ICAM5USB.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/security/RegRun_Warrior.htm">RegRun Warrior</a>:</h3>
<p><b>ICAM5USB.DLL</b><br />
Default location: %SysDir%\ICAM5USB.dll</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>ICAM5USB.DLL</strong>  is known as:</h3>
<p>Rootkit.ZeroAccess, Trojan.Sirefef, Trojan.Agent, Backdoor.Maxplus</p>
<h3><strong>ICAM5USB.DLL</strong> hash:</h3>
<ul>
<li>MD5: 11028c6a84a967070cb1286550f2058f
</div>
<div id="clist">
How to quickly detect <strong>ICAM5USB.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_MR97310_USB_DUAL_CAMERA\0000\Service: &#8220;MR97310_USB_DUAL_CAMERA&#8221;
<li>HKLM\System\CurrentControlSet\Enum\Root\LEGACY_MR97310_USB_DUAL_CAMERA\0000\DeviceDesc: &#8220;Usbstor&#8221;
<li>HKLM\System\CurrentControlSet\Services\MR97310_USB_DUAL_CAMERA\Parameters\ServiceDll: &#8220;%systemroot%\system32\ICAM5USB.dll&#8221;
<li>HKLM\System\CurrentControlSet\Services\MR97310_USB_DUAL_CAMERA\DisplayName: &#8220;Usbstor&#8221;
<li>HKLM\System\CurrentControlSet\Services\MR97310_USB_DUAL_CAMERA\Description: &#8220;Usbstor&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%WinDir%\$NtUninstallKB62478$
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SysDir%\dds_trash_log.cmd
<li>%SysDir%\ICAM5USB.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/rootkit/icam5usb-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12620&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/rootkit/icam5usb-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SECMAN.DLL is Trojan MailPassView</title>
		<link>http://greatis.com/blog/how-to-remove-malware/secman-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/secman-dll.htm#comments</comments>
		<pubDate>Tue, 08 May 2012 14:24:44 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[MailPassView]]></category>
		<category><![CDATA[SECMAN.DLL]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/secman-dll.htm</guid>
		<description><![CDATA[The file SECMAN.DLL is malware related. You must delete the file SECMAN.DLL immediately! Delete the file SECMAN.DLL without delay! Kill the process SECMAN.DLL and remove SECMAN.DLL from the Windows startup. Malware Analysis of SECMAN.DLL Full path on a computer: C:\Temp\secman.dll Detected by UnHackMe: SECMAN.DLL Default location: C:\Temp\secman.dll Removal Results: Success Number of reboot: 1 SECMAN.DLL [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>SECMAN.DLL</b> is malware related.<br />
You must delete the file <b>SECMAN.DLL</b> immediately!<br />
Delete the file <b>SECMAN.DLL</b> without delay!<br />
Kill the process <b>SECMAN.DLL</b> and remove <b>SECMAN.DLL</b> from the Windows startup.</p>
<h2>Malware Analysis of SECMAN.DLL<br />
Full path on a computer: C:\Temp\secman.dll</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>SECMAN.DLL</b><br />
Default location: C:\Temp\secman.dll</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>SECMAN.DLL</strong>  is known as:</h3>
<p>Trojan.MailPassView</p>
<h3><strong>SECMAN.DLL</strong> hash:</h3>
<ul>
<li>MD5: ccad5c9028897be6f9ea4506772232fb
</div>
<div id="clist">The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.</div>
<div id="clist">
How to quickly detect <strong>SECMAN.DLL</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}\InProcServer32\: &#8220;c:\temp\secman.dll&#8221;
<li>HKLM\Software\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}\1.0\0\win32\: &#8220;c:\temp\secman.dll&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Appdata%\Microsoft\Outlook
<li>%Local Appdata%\Microsoft\FORMS
<li>%Local Appdata%\Microsoft\Outlook
<li>%Temp%\outlook logging
<li>C:\Temp
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Local Appdata%\Microsoft\FORMS\FRMCACHE.DAT
<li>%Temp%\outlook logging\firstrun.log
<li>C:\Temp\osmax.ocx
<li>C:\Temp\Project1.exe
<li>C:\Temp\secman.dll
<li>C:\Temp\seta.bat
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/secman-dll.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12618&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/secman-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UFLM.EXE is Trojan Rimecud</title>
		<link>http://greatis.com/blog/how-to-remove-malware/uflm-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/uflm-exe.htm#comments</comments>
		<pubDate>Tue, 08 May 2012 11:47:43 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rimecud]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[UFLM.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/uflm-exe.htm</guid>
		<description><![CDATA[We checked up the file UFLM.EXE and found it hazardous. The file UFLM.EXE must be deleted from the system immediately. Kill the process UFLM.EXE and remove UFLM.EXE from the Windows startup. Malware Analysis of UFLM.EXE Full path on a computer: %Profile%\uflm.exe Detected by UnHackMe: UFLM.EXE Default location: %Profile%\uflm.exe Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>UFLM.EXE</b> and found it hazardous.<br />
The file <b>UFLM.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>UFLM.EXE</b> and remove <b>UFLM.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of UFLM.EXE<br />
Full path on a computer: %Profile%\uflm.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://www.unhackme.com">UnHackMe</a>:</h3>
<p><b>UFLM.EXE</b><br />
Default location: %Profile%\uflm.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>UFLM.EXE</strong>  is known as:</h3>
<p>Trojan.Rimecud</p>
<h3><strong>UFLM.EXE</strong> hash:</h3>
<ul>
<li>MD5: fe4b82d21f41e0721e183b412eb94b1c
</div>
<div id="clist">The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.</div>
<div id="clist">
How to quickly detect <strong>UFLM.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman: &#8220;%Profile%\uflm.exe&#8221;
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Temp%\3852.exe
<li>%Profile%\uflm.exe
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/uflm-exe.htm"></g:plusone></div><div style='clear:both'></div><img src="http://greatis.com/blog/?ak_action=api_record_view&id=12615&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/uflm-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

