Removed: _VOIDmpxvnqjpib.sys
Malware: C:\sand-box\setup01.exe
Removed: C:\WINDOWS\system32\drivers\_VOIDmpxvnqjpib.sys
—————————————————————————————————————————-
Classification:
| Antivirus | Version | Last Update | Result |
|---|---|---|---|
| F-Secure | 9.0.15370.0 | 2010.02.02 | Gen:Trojan.Heur.TP.eyW@bOWx3Rii |
| Kaspersky | 7.0.0.125 | 2010.02.01 | - |
| McAfee | 5879 | 2010.02.01 | - |
| Microsoft | 1.5406 | 2010.02.02 | - |
| NOD32 | 4825 | 2010.02.01 | - |
| Symantec | 20091.2.0.41 | 2010.02.02 | Suspicious.Insight |
—————————————————————————————————————————-
Additional information
File size: 77824 bytes
MD5 : 6bd1257f8f28a4b0ef4058be7df5c8fd
SHA1 : 4b97a869391380e63b4dee0dc8283a8ce7fa5bb6
SHA256: 6ae4f610be66d44b1cfd45081143492f4063b2fb56a15aa04f96ba2a12c3e31c
—————————————————————————————————————————-
Installation
When the program is executed, it creates the following registry subkeys and values:
———————————-
Keys added:4
———————————-
HKLM\SOFTWARE\_VOID
HKLM\SOFTWARE\_VOID\versions
HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys
HKCU\Software\Mozilla
———————————-
Values added:4
———————————-
HKLM\SOFTWARE\_VOID\affid: “traf”
HKLM\SOFTWARE\_VOID\subid: “void”
HKLM\SOFTWARE\_VOID\type: “no”
HKLM\SOFTWARE\_VOID\build: “bbr”
———————————-
Values modified:4
———————————-
HKLM\SYSTEM\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable: 0×00000001
HKLM\SYSTEM\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable: 0×00000000
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Start: 0×00000002
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Start: 0×00000004
———————————-
Files added:4
———————————-
C:\Documents and Settings\Administrator\Local Settings\Temp\_VOID567c.tmp
C:\WINDOWS\system32\drivers\_VOIDmpxvnqjpib.sys
C:\WINDOWS\system32\_VOIDhxrvtsvnnn.dat
C:\WINDOWS\system32\_VOIDmivkyxuscf.dll
———————————-
Files deleted:1
———————————-
C:\sand-box\setup01.exe
———————————-
Total changes:17
———————————-
—————————————————————————————————————————-
Detected by UnHackMe:
- none -
After first reboot detected by UnHackMe:
Item Name: _VOIDd.sys
Author:
Related File: \systemroot\system32\drivers\_VOIDmpxvnqjpib.sys
Type: Services detected by Partizan
Removal Results: Success
Number of reboot: 2
—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com
Comments
Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!



