Impove
boot up time

Run a free scan to diagnose your PC
Start Test!

Removed: srnh.lto (trojan Oficla)

May 21, 2010 by NightWatcher
Filed under: Malware 
Install UnHackMe Install RegRun

Malware: C:\sand-box\file.exe

Removed: C:\WINDOWS\system32\srnh.lto

—————————————————————————————————————————-
Detected by UnHackMe:

Item Name: shell
Author: Unknown
Related File: Explorer.exe rundll32.exe srnh.lto iqfnr
Type: System.ini

Removal Results: Success
Number of reboot: 1
—————————————————————————————————————————-
Classification:

Antivirus Version Last Update Result
F-Secure 9.0.15370.0 2010.05.19 Gen:Variant.Oficla.2
Kaspersky 7.0.0.125 2010.05.19 Trojan.Win32.Agent2.cqzi
Microsoft 1.5802 2010.05.18 Trojan:Win32/Oficla.M
NOD32 5129 2010.05.19 Win32/Oficla.GQ

—————————————————————————————————————————-
Installation
When the program is executed, it creates the following registry subkeys and values:

———————————-
Keys added:1
———————————-
HKLM\Software\Classes\idid

———————————-
Values modified:1
———————————-
(-) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: “Explorer.exe”
(+) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: “Explorer.exe rundll32.exe srnh.lto iqfnr”

———————————-
Files added:2
———————————-
C:\Documents and Settings\Administrator\Local Settings\Temp\258.tmp
C:\WINDOWS\system32\srnh.lto

———————————-
Files deleted:1
———————————-
C:\sand-box\file.exe

———————————-
Total changes:5
———————————-

—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com

Remove it now!

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!