Impove
boot up time

Run a free scan to diagnose your PC
Start Test!

Removed: vccFD.exe

December 17, 2009 by NightWatcher
Filed under: Malware 
Install UnHackMe Install RegRun

Malware: vccFD.exe
Removed: C:\Program Files\vaccf\vccFD.exe
—————————————————————————————————————————-
Classification:

Antivirus Version Last Update Result
F-Secure 9.0.15370.0 2009.12.15 Trojan.Generic.2212168
Kaspersky 7.0.0.125 2009.12.16 -
McAfee 5833 2009.12.15 Generic Downloader.x!blm
Microsoft 1.5302 2009.12.15 TrojanDownloader:Win32/Small.AO
NOD32 4691 2009.12.15 -
Symantec 1.4.4.12 2009.12.16 Downloader

—————————————————————————————————————————-
Additional information
File size: 40448 bytes
MD5   : 8fc444cd9325ec9e8fbd5aff7ddb5b6d
SHA1  : a28182185454de08fe5e6a0335dec862b9b5d7f8
SHA256: 204809e89cab5312e837d6e06da12181a11d2475b692e6058325168a4b816067
—————————————————————————————————————————-
Installation
When the program is executed, it creates the following registry subkeys and values:

———————————-
Keys added:2
———————————-
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\vaccf
HKCU\Software\vaccf

———————————-
Values added:8
———————————-
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\vcfe: “00:0C:29:82:06:4B”
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\ntick45: “34609″
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vaccf: “C:\Program Files\vaccf\vccFD.exe”
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\vaccf\UninstallString: “C:\WINDOWS\system32\uninst_vcfu.exe”
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\vaccf\DisplayName: “?e?ACA?®”
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\vaccf\HelpLink: “http://vaccine-free.co.kr”
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\vaccf\DisplayVersion: “”
HKCU\Software\vaccf\updaterVersion: “1.6″

———————————-
Files added:1
———————————-
C:\Program Files\vaccf\vccFU.exe

———————————-
Folders added:1
———————————-
C:\Program Files\vaccf

———————————-
Total changes:12
———————————-

—————————————————————————————————————————-
Detected by UnHackMe:

Item Name: vaccf
Author:
Related File: C:\Program Files\vaccf\vccFD.exe
Type: Registry Run

Removal Results: Success
Number of reboot: 1
—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com

Remove it now!

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!