Impove
boot up time

Run a free scan to diagnose your PC
Start Test!

Removed: _VOIDmpxvnqjpib.sys

February 3, 2010 by NightWatcher
Filed under: Malware 
Install UnHackMe Install RegRun

Malware: C:\sand-box\setup01.exe
Removed: C:\WINDOWS\system32\drivers\_VOIDmpxvnqjpib.sys
—————————————————————————————————————————-
Classification:

Antivirus Version Last Update Result
F-Secure 9.0.15370.0 2010.02.02 Gen:Trojan.Heur.TP.eyW@bOWx3Rii
Kaspersky 7.0.0.125 2010.02.01 -
McAfee 5879 2010.02.01 -
Microsoft 1.5406 2010.02.02 -
NOD32 4825 2010.02.01 -
Symantec 20091.2.0.41 2010.02.02 Suspicious.Insight

—————————————————————————————————————————-
Additional information
File size: 77824 bytes
MD5 : 6bd1257f8f28a4b0ef4058be7df5c8fd
SHA1 : 4b97a869391380e63b4dee0dc8283a8ce7fa5bb6
SHA256: 6ae4f610be66d44b1cfd45081143492f4063b2fb56a15aa04f96ba2a12c3e31c
—————————————————————————————————————————-
Installation
When the program is executed, it creates the following registry subkeys and values:

———————————-
Keys added:4
———————————-
HKLM\SOFTWARE\_VOID
HKLM\SOFTWARE\_VOID\versions
HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys
HKCU\Software\Mozilla

———————————-
Values added:4
———————————-
HKLM\SOFTWARE\_VOID\affid: “traf”
HKLM\SOFTWARE\_VOID\subid: “void”
HKLM\SOFTWARE\_VOID\type: “no”
HKLM\SOFTWARE\_VOID\build: “bbr”

———————————-
Values modified:4
———————————-
HKLM\SYSTEM\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable: 0×00000001
HKLM\SYSTEM\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable: 0×00000000
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Start: 0×00000002
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Start: 0×00000004

———————————-
Files added:4
———————————-
C:\Documents and Settings\Administrator\Local Settings\Temp\_VOID567c.tmp
C:\WINDOWS\system32\drivers\_VOIDmpxvnqjpib.sys
C:\WINDOWS\system32\_VOIDhxrvtsvnnn.dat
C:\WINDOWS\system32\_VOIDmivkyxuscf.dll

———————————-
Files deleted:1
———————————-
C:\sand-box\setup01.exe

———————————-
Total changes:17
———————————-

—————————————————————————————————————————-
Detected by UnHackMe:

- none -

After first reboot detected by UnHackMe:

Item Name: _VOIDd.sys
Author:
Related File: \systemroot\system32\drivers\_VOIDmpxvnqjpib.sys
Type: Services detected by Partizan

Removal Results: Success
Number of reboot: 2
—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com

Remove it now!

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!