Malware: Microsoft Windows 7 Ultimate Validator + Activation.exe (trojan Injector – change Windows HOSTS file)

February 2, 2011 by NightWatcher
Filed under: Malware 
: Solved!

You should Download Removal Tool here...

Malware: Microsoft Windows 7 Ultimate Validator + Activation.exe

—————————————————————————————————————————-
How to quickly detect malware presence?

Files modified:
C:\WINDOWS\system32\drivers\etc\hosts

New files:
C:\Documents and Settings\Administrator\Local Settings\Temp\%temp%.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\%tmp%.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\WER9710.dir00\appcompat.txt
C:\Documents and Settings\Administrator\Local Settings\Temp\WER9710.dir00\manifest.txt
C:\Documents and Settings\Administrator\Local Settings\Temp\WER9710.dir00\svchost.exe.hdmp
C:\Documents and Settings\Administrator\Local Settings\Temp\WER9710.dir00\svchost.exe.mdmp
C:\Documents and Settings\Administrator\Local Settings\Temp\winamp\svchost.exe
—————————————————————————————————————————-
Classification:

Antivirus Version Last Update Result
F-Secure 9.0.16160.0 2011.01.31 -
Kaspersky 7.0.0.125 2011.01.31 -
Microsoft 1.6502 2011.01.31 VirTool:MSIL/Injector.J
NOD32 5832 2011.01.30 a variant of MSIL/Injector.CH

—————————————————————————————————————————-

MD5 49a4f5e5659273a34096dd003649077f

SHA1 18a00cb69a954b679cf6832293a76169eb3b62dc

SHA256 b06a9b46836ae8296630a35359ef1d33b820c879afe0b22318293a62530b1a46

—————————————————————————————————————————-


Installation
When the program is executed, it creates the following registry subkeys and values:

———————————-
Keys added:2
———————————-
HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags
HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers

———————————-
Values added:1
———————————-
HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Documents and Settings\Administrator\Local Settings\Temp\winamp\svchost.exe: “EnableNXShowUI”

———————————-
Files added:7
———————————-
C:\Documents and Settings\Administrator\Local Settings\Temp\%temp%.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\%tmp%.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\WER9710.dir00\appcompat.txt
C:\Documents and Settings\Administrator\Local Settings\Temp\WER9710.dir00\manifest.txt
C:\Documents and Settings\Administrator\Local Settings\Temp\WER9710.dir00\svchost.exe.hdmp
C:\Documents and Settings\Administrator\Local Settings\Temp\WER9710.dir00\svchost.exe.mdmp
C:\Documents and Settings\Administrator\Local Settings\Temp\winamp\svchost.exe

———————————-
Files [attributes?] modified:1
———————————-
C:\WINDOWS\system32\drivers\etc\hosts

———————————-
Folders added:2
———————————-
C:\Documents and Settings\Administrator\Local Settings\Temp\WER9710.dir00
C:\Documents and Settings\Administrator\Local Settings\Temp\winamp

———————————-
Total changes:13
———————————-

The HOSTS file contains:
—————————————————————————————————————————-
127.0.0.1 www.virustotal.com
127.0.0.1 virustotal.com
127.0.0.1 novirusthanks.org
127.0.0.1 vscan.novirusthanks.org
127.0.0.1 virusscan.jotti.org
127.0.0.1 www.virusscan.jotti.org
127.0.0.1 virscan.org
127.0.0.1 www.virscan.org
127.0.0.1 virus-trap.org
127.0.0.1 www.virus-trap.org
127.0.0.1 filterbit.com
127.0.0.1 www.filterbit.com
127.0.0.1 viruschief.com
127.0.0.1 www.viruschief.com
127.0.0.1 kaspersky.com
127.0.0.1 www.kaspersky.com

—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com


Recommended: UnHackMe anti-rootkit and anti-malware

Premium software: RegRun Security Suite (Good choice for removal and protection)

Written by

Malware Hunter.

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!

You must be logged in to post a comment.