antyvirk.exe – Porn-Dialer Plsex
We checked up the file antyvirk.exe and found it hazardous.
The file antyvirk.exe must be deleted from the system immediately.
Kill the process antyvirk.exe and remove antyvirk.exe from the Windows startup.
Malware: gay-filmy-zdjecia.exe
Removed: C:\WINDOWS\antyvirk.exe
—————————————————————————————————————————-
Detected by UnHackMe in “Multi AntiVirus Scan” mode:
ANTYVIRK.EXE
Default location: C:\WINDOWS\ANTYVIRK.EXE
MD5: 78BF70AFB37E295B4F0CD23E6B2C09A8
SHA1: B95E7BAB 16E39658 BD3B57A5 548A0785 5A111D29
File Size: 50 856
Removal Results: Success
Number of reboot: 1
—————————————————————————————————————————-
How to quickly detect malware presence?
Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\AntyVirK
Value: “c:\windows\antyvirk.exe ukrt ”
Files:
C:\Documents and Settings\All Users\Desktop\Ulubione strony.exe
C:\WINDOWS\antyvirk.exe
—————————————————————————————————————————-
Classification:
| Antivirus | Version | Last Update | Result |
|---|---|---|---|
| F-Secure | 9.0.16160.0 | 2011.02.02 | Dialer.Plsex.X |
| Kaspersky | 7.0.0.125 | 2011.02.02 | not-a-virus:Porn-Dialer.Win32.Plsex |
| Microsoft | 1.6502 | 2011.02.02 | Dialer:Win32/Ulubione |
| NOD32 | 5841 | 2011.02.02 | a variant of Win32/Dialer.Erodial |
—————————————————————————————————————————-
MD5 78bf70afb37e295b4f0cd23e6b2c09a8
SHA1 b95e7bab16e39658bd3b57a5548a07855a111d29
SHA256 645334c741911b3d9a03d92bb850d72a7f3115c434abbe60964824ade4e8c8dd
—————————————————————————————————————————-
Installation
When the program is executed, it creates the following registry subkeys and values:
———————————-
Keys added:1
———————————-
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\CONNECT
———————————-
Values added:3
———————————-
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\AntyVirK: “c:\windows\antyvirk.exe ukrt ”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\CONNECT\UninstallString: “c:\windows\antyvirk.exe usuk ”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\CONNECT\DisplayName: “CONNECT”
———————————-
Files added:2
———————————-
C:\Documents and Settings\All Users\Desktop\Ulubione strony.exe
C:\WINDOWS\antyvirk.exe
———————————-
Total changes:6
———————————-
—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com
Recommended: UnHackMe anti-rootkit and anti-malware
Premium software: RegRun Security Suite (Good choice for removal and protection)




