Impove
boot up time

Run a free scan to diagnose your PC
Start Test!

Removed: svchost.exe

January 21, 2010 by NightWatcher
Filed under: Malware 
Install UnHackMe Install RegRun

Malware: server.exe
Removed: C:\WINDOWS\system32\awServ\svchost.exe
—————————————————————————————————————————-
Classification:

Antivirus Version Last Update Result
F-Secure 9.0.15370.0 2010.01.21 -
Kaspersky 7.0.0.125 2010.01.21 Trojan.Win32.Refroso.aiuw
McAfee 5867 2010.01.20 -
Microsoft 1.5302 2010.01.20 -
NOD32 4791 2010.01.20 probably a variant of Win32/Injector.AQN
Symantec 20091.2.0.41 2010.01.21 -

—————————————————————————————————————————-
Additional information
File size: 455129 bytes
MD5 : 14aa4ae3008eeba8ddc6035acbbcf937
SHA1 : fb974d9a14205a36eeb75d8d5cacfece0b7eb96a
SHA256: 84b41824d5c8543247d7b8c0d2db1094ef0755d43a81ffd479238a525197d0d0
—————————————————————————————————————————-
Installation
When the program is executed, it creates the following registry subkeys and values:

———————————-
Keys added:4
———————————-
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{0EFEF0FD-7337-BEF0-339B-5CF28A9AA0D5}
HKLM\SOFTWARE\Bifrost
HKLM\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
HKCU\Software\Bifrost

———————————-
Values added:3
———————————-
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{0EFEF0FD-7337-BEF0-339B-5CF28A9AA0D5}\stubpath: “C:\WINDOWS\system32\awServ\svchost.exe s”
HKLM\SOFTWARE\Bifrost\nck: ED 1B E6 27 B9 28 D6 32 74 C3 CD 74 FA 93 5B 67
HKCU\Software\Bifrost\klg: 01

———————————-
Files added:4
———————————-
C:\Documents and Settings\Administrator\Application Data\addon.dat
C:\Documents and Settings\Administrator\Local Settings\Temp\1.scr
C:\WINDOWS\system32\awServ\klog.dat
C:\WINDOWS\system32\awServ\svchost.exe

———————————-
Folders added:1
———————————-
C:\WINDOWS\system32\awServ

———————————-
Total changes:12
———————————-

—————————————————————————————————————————-
Detected by UnHackMe:

Item Name: {0EFEF0FD-7337-BEF0-339B-5CF28A9AA0D5}
Author: Unknown
Related File: C:\WINDOWS\system32\awServ\svchost.exe s
Type: ActiveSetup

Removal Results: Success
Number of reboot: 1
—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com

Remove it now!

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!