Removed: C:\Documents and Settings\All Users\Application Data\BrEaK\Break.exe (trojan Bancos)
Malware: mobile5.exe
Removed: C:\Documents and Settings\All Users\Application Data\BrEaK\Break.exe
—————————————————————————————————————————-
Detected by UnHackMe:
Item Name: Break.exe Espanha
Author: Home Basic
Related File: C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\BREAK\BREAK.EXE
Type: Registry Run
Item Name: Break.exe
Author: Home Basic
Related File: C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\BREAK\BREAK.EXE
Type: Running Processes
Removal Results: Success
Number of reboot: 1
—————————————————————————————————————————-
How to quickly detect malware presence?
Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Break.exe Espanha
Value: “C:\Documents and Settings\All Users\Application Data\BrEaK\Break.exe”
Folders: C:\Documents and Settings\All Users\Application Data\BrEaK\
Files: C:\Documents and Settings\All Users\Application Data\BrEaK\Break.exe
—————————————————————————————————————————-
| Antivirus | Version | Last Update | Result |
|---|---|---|---|
| F-Secure | 9.0.15370.0 | 2010.09.01 | - |
| Kaspersky | 7.0.0.125 | 2010.09.01 | Trojan-Downloader.Win32.Agent.ekyk |
| Microsoft | 1.6103 | 2010.09.01 | TrojanSpy:Win32/Bancos.VY |
| NOD32 | 5416 | 2010.09.01 | - |
—————————————————————————————————————————-
Additional information
Additional informationShow all
MD5 : 00166b8e72e0d962b0cbe64280575954
SHA1 : c4078ab221c7511ec2c570cce912443455ac24ea
SHA256: 64b4a999940a62e1887e78394d121f84129213936bb2806214f19ef302cea030
—————————————————————————————————————————-
Installation
When the program is executed, it creates the following registry subkeys and values:
———————————-
Keys added:1
———————————-
HKCU\Software\BrEaK
———————————-
Values added:2
———————————-
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Break.exe Espanha: “C:\Documents and Settings\All Users\Application Data\BrEaK\Break.exe”
HKCU\Software\BrEaK\Ativ/Desa: 0×00000000
———————————-
Files added:1
———————————-
C:\Documents and Settings\All Users\Application Data\BrEaK\Break.exe
———————————-
Folders added:1
———————————-
C:\Documents and Settings\All Users\Application Data\BrEaK
———————————-
Total changes:5
———————————-
—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com
Comments
Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!



