antyvirk.exe – Porn-Dialer Plsex

February 23, 2011 by NightWatcher
Filed under: Not-a-Virus 
: Solved!

You should Download Removal Tool here...

We checked up the file antyvirk.exe and found it hazardous.
The file antyvirk.exe must be deleted from the system immediately.
Kill the process antyvirk.exe and remove antyvirk.exe from the Windows startup.

Malware: gay-filmy-zdjecia.exe

Removed: C:\WINDOWS\antyvirk.exe

Detected by UnHackMe in “Multi AntiVirus Scan” mode:

Default location: C:\WINDOWS\ANTYVIRK.EXE
MD5: 78BF70AFB37E295B4F0CD23E6B2C09A8
SHA1: B95E7BAB 16E39658 BD3B57A5 548A0785 5A111D29
File Size: 50 856

Removal Results: Success
Number of reboot: 1

How to quickly detect malware presence?

Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\AntyVirK
Value: “c:\windows\antyvirk.exe ukrt ”

C:\Documents and Settings\All Users\Desktop\Ulubione strony.exe

Antivirus Version Last Update Result
F-Secure 9.0.16160.0 2011.02.02 Dialer.Plsex.X
Kaspersky 2011.02.02 not-a-virus:Porn-Dialer.Win32.Plsex
Microsoft 1.6502 2011.02.02 Dialer:Win32/Ulubione
NOD32 5841 2011.02.02 a variant of Win32/Dialer.Erodial


MD5 78bf70afb37e295b4f0cd23e6b2c09a8

SHA1 b95e7bab16e39658bd3b57a5548a07855a111d29

SHA256 645334c741911b3d9a03d92bb850d72a7f3115c434abbe60964824ade4e8c8dd


When the program is executed, it creates the following registry subkeys and values:

Keys added:1

Values added:3
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\AntyVirK: “c:\windows\antyvirk.exe ukrt ”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\CONNECT\UninstallString: “c:\windows\antyvirk.exe usuk ”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\CONNECT\DisplayName: “CONNECT”

Files added:2
C:\Documents and Settings\All Users\Desktop\Ulubione strony.exe

Total changes:6

Recommended software:
UnHackMe anti-rootkit and anti-malware
RegRun Security Suite (Good choice for removal and protection)

Recommended: UnHackMe anti-rootkit and anti-malware

Premium software: RegRun Security Suite (Good choice for removal and protection)

Written by

Malware Hunter.


Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!

You must be logged in to post a comment.