Removed: ..\Administrator\ntload.dll, ..\system32\notepad.dll, ..Start Menu\Programs\Startup\scandisk.dll

Malware: pm.exe —————————————————————————————————————————- Removed: C:\Documents and Settings\ Administrator\ntload.dll C:\WINDOWS\system32\notepad.dll C:\Documents and Settings\Administrator\ Start Menu\Programs\Startup\scandisk.dll —————————————————————————————————————————- Detected by UnHackMe: Item Name: notepad Author: Unknown Related File: C:\DOCUME~1\ADMINI~1\NTLOAD.DLL Type: Registry Run Item Name: notepad Author: Unknown Related File: C:\WINDOWS\SYSTEM32\NOTEPAD.DLL Type: Registry Run After first reboot detected by UnHackMe: Item Name: scandisk.dll Author: Unknown Related File: C:\DOCUMENTS AND […]
More…

Removed: _VOIDd.sys

Malware: C:\sand-box\install01.exe —————————————————————————————————————————- Removed: C:\WINDOWS\_VOIDtpdwqienbv\_VOIDd.sys —————————————————————————————————————————- After first reboot detected by UnHackMe: Item Name: _VOIDtpdwqienbv Author: Related File: C:\WINDOWS\_VOIDTPDWQIENBV\_VOIDD.SYS Type: Services detected by Partizan Item Name: _VOIDd.sys Author: Related File: \systemroot\system32\drivers\_VOIDbfjpaypdiv.sys Type: Services detected by Partizan Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result Kaspersky 7.0.0.125 2010.04.02 Trojan.Win32.Tdss.azxa McAfee […]
More…

Removed: ..Application Data\xspecmod\x.dll

Malware: install.exe —————————————————————————————————————————- Removed: C:\Documents and Settings\Administrator\ Application Data\xspecmod\x.dll —————————————————————————————————————————- Detected by UnHackMe: Item Name: {D353732A-360F-47B6-AE4E-57C491600108} Author: Timonin & Co Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\XSPECMOD\X.DLL Type: Browser Helper Objects Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.15 – Kaspersky 7.0.0.125 2010.04.15 Trojan-Dropper.Win32.Agent.bvrx McAfee 5.400.0.1158 2010.04.15 […]
More…

Removed: C:\WINDOWS\system32\actmoviel.exe (random filename)

Malware: update.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\actmoviel.exe (random filename) —————————————————————————————————————————- Detected by UnHackMe: Item Name: xmlprovVSS Author: Related File: C:\WINDOWS\system32\actmoviel.exe srv Type: Auto Services Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.08 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.04.08 Trojan.Win32.Cosmu.vyz Microsoft 1.5605 2010.04.08 Trojan:Win32/Malagent NOD32 5011 2010.04.08 Win32/IRCBot.NBC —————————————————————————————————————————- Additional information […]
More…

Removed: csrcs.exe, ..\SYSTEM32\AUTORUN.INF

Malware: vvbxua.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\csrcs.exe C:\WINDOWS\SYSTEM32\AUTORUN.INF —————————————————————————————————————————- Detected by UnHackMe: Item Name: shell Author: Unknown Related File: Explorer.exe csrcs.exe Type: System.ini Item Name: csrcs Author: Unknown Related File: C:\WINDOWS\SYSTEM32\CSRCS.EXE Type: Explorer Run Item Name: csrcs.exe Author: Unknown Related File: C:\WINDOWS\SYSTEM32\CSRCS.EXE Type: Detected using Heuristic Algorithm Item Name: autorun.inf Author: Unknown Related File: C:\WINDOWS\SYSTEM32\AUTORUN.INF Type: Detected […]
More…

Removed: ..\Application Data\ufxw.exe

Malware: img049.pif.exe —————————————————————————————————————————- Removed: C:\Documents and Settings\ Administrator\Application Data\ufxw.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: taskman Author: Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\UFXW.EXE Type: Winlogon System Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.13 Gen:Heur.Krypt.10 Kaspersky 7.0.0.125 2010.04.13 – McAfee 5.400.0.1158 2010.04.13 – Microsoft 1.5605 2010.04.13 […]
More…

Removed: ..\Local Settings\Temp\7749423160.dll (random filename)

Malware: exe.exe —————————————————————————————————————————- Removed: C:\Documents and Settings\Administrator\ Local Settings\Temp\7749423160.dll (random filename) —————————————————————————————————————————- Detected by UnHackMe: Item Name: SysTray Author: Unknown Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\7749423160.DLL Type: Shell Services DelayLoad After first reboot detected by UnHackMe: Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.08 – Kaspersky 7.0.0.125 2010.04.08 Worm.Win32.AutoRun.bfop […]
More…

Removed: ..\Digital Protection\digext.dll, ..\Local Settings\Temp\davclnt.exe, ..\Digital Protection\digprot.exe (Fake AV – Digital Protection aka Paladin Antivirus)

Malware: C:\sand-box\ be0e191c4124f43fc44575747c295299.exe —————————————————————————————————————————- Removed: C:\Program Files\Digital Protection\digext.dll C:\Documents and Settings\Administrator\ Local Settings\Temp\davclnt.exe C:\Program Files\Digital Protection\digprot.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.12 Gen:Variant.TDss.2 Kaspersky 7.0.0.125 2010.04.12 – McAfee 5.400.0.1158 2010.04.12 DNSChanger.bf Microsoft 1.5605 2010.04.12 Trojan:Win32/FakeCog NOD32 5022 2010.04.12 a variant of Win32/Kryptik.CPZ —————————————————————————————————————————- Additional information File size: 260096 bytes MD5 : […]
More…

Removed: \NetMeeting\oqest.lib, ..\Google\tvulo.lib, ..\rygug\ypnlr.lib

Malware: yuyanzhe.exe —————————————————————————————————————————- Removed: C:\Program Files\NetMeeting\oqest.lib C:\Program Files\Google\tvulo.lib C:\Program Files\rygug\ypnlr.lib —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.13 – Kaspersky 7.0.0.125 2010.04.13 Trojan-Downloader.Win32.VB.wnp McAfee 5.400.0.1158 2010.04.13 Artemis!02CDBBE3B25F Microsoft 1.5605 2010.04.13 – NOD32 5024 2010.04.13 – —————————————————————————————————————————- Additional information File size: 20480 bytes MD5 : 02cdbbe3b25f3864fc2dc56fc0812fad SHA1 : fa0aface567b3186fea449b7c1d49fe24a10625a SHA256: 8400a07a277347ee61b35bbfb67a9ae3002b4011e4d23e56f792e42fac1c6137 —————————————————————————————————————————- Detected by […]
More…

Removed: ..\Administrator\vkheop.exe (random filename)

Malware: C:\sand-box\ 588cebbb1597355920803e6f24caa855.exe —————————————————————————————————————————- Removed: C:\Documents and Settings\Administrator\vkheop.exe (random filename) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.12 – Kaspersky 7.0.0.125 2010.04.12 – McAfee 5.400.0.1158 2010.04.13 – Microsoft 1.5605 2010.04.13 – NOD32 5023 2010.04.12 – —————————————————————————————————————————- Additional information File size: 74752 bytes MD5 : d2542afa881146780e584b9bfa3d0f92 SHA1 : b83d8553c976db4986c556f0f1afa0be91016567 SHA256: 254a3d166ba8a8ccaf548142879f3df180c62941e978c77ca0ab262a40d9a19f —————————————————————————————————————————- Detected by […]
More…

Removed: sdra64.exe, SVSHOST.DLL, WININET.EXE, LMSXSLTSSO.DLL, MSXSLTSSO.DLL, gtk4.tmp

Malware: C:\sand-box\load.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\sdra64.exe C:\WINDOWS\SYSTEM32\SVSHOST.DLL C:\WINDOWS\SYSTEM32\WININET.EXE C:\WINDOWS\SYSTEM32\LMSXSLTSSO.DLL C:\WINDOWS\SYSTEM32\MSXSLTSSO.DLL C:\Documents and Settings\Administrator\Local Settings\Temp\gtk4.tmp —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.12 Trojan.Peed.Gen Kaspersky 7.0.0.125 2010.04.12 – Microsoft 1.5605 2010.04.12 TrojanDownloader:Win32/Otlard.B NOD32 5020 2010.04.12 – —————————————————————————————————————————- Additional information File size: 24064 bytes MD5 : a8569f1595bda19abcbbb47f68af59b4 SHA1 : 18c5cd37315f0044c1ae11d89abcf8618ca1d378 SHA256: c638ca420ec0b43b688f428a278564f42d15ddb124b15f6a1b56f0ed8988fd02 —————————————————————————————————————————- Detected by UnHackMe: […]
More…

Removed: ..\system32\overlapp32.dll

Malware: C:\sand-box\1.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\overlapp32.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.04 Trojan.Spy.Banker.ACLA Kaspersky 7.0.0.125 2010.04.04 Trojan-Banker.Win32.Banbra.vbk McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.04.04 TrojanSpy:Win32/Banbra.M NOD32 4999 2010.04.04 Win32/Spy.Banker.TLA —————————————————————————————————————————- Additional information File size: 27679 bytes MD5 : f4ae42f9bb6b8243254b09048865c3ed SHA1 : 246527caf94dd07b2ffb04100fa5e8b7b9177980 SHA256: d8456caf15ec23243bc8a988c792503d90323c1604ced76f90a5e3a941094c0e —————————————————————————————————————————- Detected by UnHackMe: Item Name: WebCheck Author: […]
More…

Removed: ..application data\systemproc\lsass.exe

Malware: load.exe —————————————————————————————————————————- Removed: c:\documents and settings\administrator\application data\systemproc\lsass.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.12 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.04.12 P2P-Worm.Win32.Agent.aam Microsoft 1.5605 2010.04.12 VirTool:Win32/VBInject.FB NOD32 5021 2010.04.12 probably a variant of Win32/Injector.BHD —————————————————————————————————————————- Additional information File size: 299008 bytes MD5   : d11d76c6ecf6a9a87dcd510294104a66 SHA1  : ed147998d1435ac667fd05165013d11a5e24b846 SHA256: a5a9100a3a614de13b8a660714f499bebca125b2dbb21e9d40072aa13b887f77 —————————————————————————————————————————- Detected by UnHackMe: Item Name: RTHDBPL Author: […]
More…

Removed: fisbdn.jpg.exe

Malware: C:\sand-box\fisbdn.jpg.exe —————————————————————————————————————————- Removed: C:\sand-box\fisbdn.jpg.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.08 – Kaspersky 7.0.0.125 2010.04.07 Trojan.Win32.VB.adro Microsoft 1.5605 2010.04.08 – NOD32 5008 2010.04.07 a variant of Win32/VB.OWR —————————————————————————————————————————- Additional information File size: 118784 bytes MD5 : 66f42e402a841a4382e6123bcfd1f398 SHA1 : d8dae90bd942637ddc542578ed9c3b9edd07466e SHA256: bc9ea163322765d3aaad79e29f5ff93cd67e1c0c10a21b7eeb780b14176978a6 —————————————————————————————————————————- Detected by UnHackMe: Item Name: fisbdn.jpg Author: . […]
More…

Removed: C:\WINDOWS\csrssm.exe

Malware: decogim.exe —————————————————————————————————————————- Removed: C:\WINDOWS\csrssm.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.12 – Kaspersky 7.0.0.125 2010.04.12 – Microsoft 1.5605 2010.04.12 – NOD32 5021 2010.04.12 – —————————————————————————————————————————- Additional information File size: 180224 bytes MD5   : b07926161f537dfcf849d52b2f46e447 SHA1  : 5f481ece392eb4e055c2470bb866f7e30f052d11 SHA256: fb4c0f54afcd286ffa1366cf5e0da65db5dc834acba4fe0ecbe0e3d9b07953f2 —————————————————————————————————————————- Detected by UnHackMe: Item Name: UserInit Author: Unknown Related File: C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\csrssm.exe Type: UserInit Value […]
More…

Removed: ..\Your Protection\urpext.dll, ..\Local Settings\Temp\dbnetlib.exe ..\Your Protection\urpprot.exe, _VOIDd.sys (FakeAV – Your Protection aka Paladin Antivirus)

Malware: C:\sand-box\adobeflashplayerv10.0.45.2.exe —————————————————————————————————————————- Removed: C:\Program Files\Your Protection\urpext.dll C:\Documents and Settings\Administrator\ Local Settings\Temp\dbnetlib.exe C:\Program Files\Your Protection\urpprot.exe C:\WINDOWS\_VOIDpspesecxvd\_VOIDd.sys —————————————————————————————————————————- —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.31 – Kaspersky 7.0.0.125 2010.03.31 – McAfee 5936 2010.03.30 – Microsoft 1.5605 2010.03.30 – NOD32 4986 2010.03.30 – —————————————————————————————————————————- Additional information File size: 21504 bytes MD5   : ead8c61eb0cc0e387dbd4d95c99a4880 SHA1  : 2c04a6a0cf910da45e7c0e8179d4213fac4eeb8a SHA256: […]
More…

Removed: ..\system32\booyaka.exe

Malware: install.exe_crypted.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\booyaka.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.10 – Kaspersky 7.0.0.125 2010.04.10 Trojan.Win32.Agent.drbz Microsoft 1.5605 2010.04.10 Trojan:Win32/SystemHijack.gen NOD32 5014 2010.04.09 a variant of Win32/Kryptik.DMN —————————————————————————————————————————- Additional information File size: 14336 bytes MD5 : 9f27bd22e02b5d00075665e6b3a8ac54 SHA1 : 0aaba8ac731f3fce77f75ff9964fc4c0dea286e7 SHA256: 6401cd5d914b9b473f5d0d5f4f13a9634392a831f40888bd5d453ed23a0e6440 —————————————————————————————————————————- Detected by UnHackMe: Item Name: UserInit Author: Unknown […]
More…

Removed: sp.DLL

Malware: bot_freewebship_1.8.0.exe —————————————————————————————————————————- Removed: C:\Documents and Settings\All Users\Application Data\Ashampoo\sp.DLL —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.07 – Kaspersky 7.0.0.125 2010.04.07 Trojan-Proxy.Win32.Agent.cgb Microsoft 1.5605 2010.04.07 TrojanDropper:Win32/Malf.gen NOD32 5006 2010.04.07 Win32/Agent.QZF —————————————————————————————————————————- Additional information File size: 55296 bytes MD5 : c5efacd3727b664c9f93717a2dce4823 SHA1 : 405c069ad635c58a325f8eaadcb3c85e5731b534 SHA256: 29d368e8afe1d9ea1ba6787bce8edb93432df4cc147101585dfc28d45690eb57 —————————————————————————————————————————- Detected by UnHackMe: Item Name: sp Author: […]
More…

Removed: C:\WINDOWS\system32\System

Malware: jsinstall.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\System —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.08 Gen:Trojan.Heur.XG0@tnBPfXkce Kaspersky 7.0.0.125 2010.04.08 Trojan-Spy.Win32.Agent.beqx Microsoft 1.5605 2010.04.08 – NOD32 5011 2010.04.08 Win32/Delf.PEN —————————————————————————————————————————- Additional information File size: 817664 bytes MD5 : 9024799ca8a20474a7858d6377126ec6 SHA1 : c8ac8c7cd9726ac6a5ec6b4cf07189aa3c52e200 SHA256: 2dddc6cdd5d7fa4c17089369fffc1be3a42c180a2b2f2403224fc4626f9b964b —————————————————————————————————————————- Detected by UnHackMe: Item Name: serviceJS Author: Microsoft Related File: C:\WINDOWS\system32\System […]
More…

Removed: ..\Local Settings\Temp\Office.exe, codigoHpeS651B.exe

Malware: c:\sand-box\codigoHpeS651B.exe —————————————————————————————————————————- Removed: C:\Documents and Settings\Administrator\ Local Settings\Temp\Office.exe c:\sand-box\codigoHpeS651B.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.08 – Kaspersky 7.0.0.125 2010.04.07 – Microsoft 1.5605 2010.04.08 – NOD32 5008 2010.04.07 Win32/Spy.Banker.PBS —————————————————————————————————————————- Additional information File size: 1801227 bytes MD5   : 4b538a11b92a11d966619c1b37c971ec SHA1  : e4406ff2170de78fde1607c4977a118d97620cca SHA256: dd17855f0190cb917a7949f0b6c0eafc57d8734ae46c774b678d1d204e2e71a7 —————————————————————————————————————————- Detected by UnHackMe: Item Name: codigoHpeS651B.exe Author: 0oooo Related […]
More…

Removed: ..\system32\keepsafe.exe / Restored: ..\system32\ctfmon.exe

Malware: laoshuxzz1.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\keepsafe.exe —————————————————————————————————————————- Restored: C:\WINDOWS\system32\ctfmon.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.05 – Kaspersky 7.0.0.125 2010.04.05 Trojan.Win32.Antavmu.hgs Microsoft 1.5605 2010.04.05 TrojanDownloader:Win32/Small.gen!D NOD32 4999 2010.04.04 – —————————————————————————————————————————- Additional information File size: 49152 bytes MD5   : e0a226485796d0976200bdcd2d3456ad SHA1  : cc40e22de18f537fb0c0d1798c12db322d69e87b SHA256: c5d7d812d8503743a0af2485d715fea5182926ba58e2a1961dc1b75201faa8b1 —————————————————————————————————————————- Detected by UnHackMe: Item Name: TXMouie Author: Unknown Related File: C:\WINDOWS\SYSTEM32\KEEPSAFE.EXE […]
More…

Removed: ..\drivers\ndisoko.sys, ..\system32\certoko.dll

Malware: C:\sand-box\steinberg_cubase_sx-keygen.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\drivers\ndisoko.sys C:\WINDOWS\system32\certoko.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.09 Trojan.Generic.3587235 Kaspersky 7.0.0.125 2010.04.09 Trojan-Dropper.Win32.Koobface.z Microsoft 1.5605 2010.04.09 TrojanDropper:Win32/Koobface.J NOD32 5014 2010.04.09 a variant of Win32/Tinxy.BJ —————————————————————————————————————————- Additional information File size: 229376 bytes MD5   : f3bdee76975380ab3bf574c9bb3bca38 SHA1  : 327243c4d810e992d57d09562e9f5c6c33a9fc99 SHA256: 899471037bc87cfb2c212f19ffdb8c7a0de625c52e57f18dd74ac12d87ee607a —————————————————————————————————————————- Detected by UnHackMe: Item Name: ipokoraid Author: Comfort Software Group […]
More…

Removed: ..\system32\wintems.exe

Malware: b64_3.jpg.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\wintems.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.01 Win32.Bagle.SUQ@mm Kaspersky 7.0.0.125 2010.04.01 Email-Worm.Win32.Bagle.of McAfee 5937 2010.03.31 W32/Bagle.gen Microsoft 1.5605 2010.03.31 Worm:Win32/Bagle.gen!C NOD32 4989 2010.03.31 Win32/Bagle.TK —————————————————————————————————————————- Additional information File size: 71684 bytes MD5 : 98bfade6aaaf5b5acea2be97c3614e95 SHA1 : 9e6aff8fe4562e183b8c44f34c0945a0a75cd87b SHA256: dee0a252d21eb9bc44a9903290d7ec31f541c062fac1bd1f00aeecd7be842119 —————————————————————————————————————————- Detected by UnHackMe: Item Name: german.exe Author: […]
More…

Restored: ..\system32\dsound.dll, ..\system32\olepro32.dll

Malware: C:\sand-box\QQHX.exe —————————————————————————————————————————- Restored: C:\WINDOWS\system32\dsound.dll C:\WINDOWS\system32\olepro32.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.07 Trojan-PSW:W32/OnlineGames.TYA Kaspersky 7.0.0.125 2010.04.07 Trojan.Win32.Vilsel.tux Microsoft 1.5605 2010.04.07 PWS:Win32/OnLineGames.GP NOD32 5006 2010.04.07 a variant of Win32/PSW.OnLineGames.OQU —————————————————————————————————————————- Additional information File size: 25656 bytes MD5 : 1426bbb0b5f1e7c43cfbde14c65e0dd1 SHA1 : d3bd0b8036c699daf7357e8019db23549aae98c5 SHA256: 50ab8f874d141961a9ac247793f7c059be7418a1ed2c69573d5cf95ef9286aa1 —————————————————————————————————————————- Detected by UnHackMe in “Multi AV Scan” […]
More…

Removed: ..\Application Data\m\flec006.exe

Malware: b64.jpg.exe Removed: C:\Documents and Settings\Administrator\Application Data\m\flec006.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.01 Win32.Bagle.SUQ@mm Kaspersky 7.0.0.125 2010.04.01 Email-Worm.Win32.Bagle.of McAfee 5937 2010.03.31 W32/Bagle.gen Microsoft 1.5605 2010.03.31 Worm:Win32/Bagle.gen!C NOD32 4989 2010.03.31 Win32/Bagle.TK —————————————————————————————————————————- Additional information File size: 99332 bytes MD5 : 3d5dfa9558bdb1db7f3291ea781f004e SHA1 : 59fdabb403530d9606413566b4858bf33c68bcd1 SHA256: 27bba76a4a527520d4c32a8532b1d91efa18a6853db6c2b5ac6ab2cc8fb1b7af —————————————————————————————————————————- Installation When the program is […]
More…

Removed: C:\Win\lsass.exe

Malware: 1544e334965af8becf6c767059890997.exe Removed: C:\Win\lsass.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.06 Gen:Trojan.Heur.HmNfrbUYmYkib Kaspersky 7.0.0.125 2010.01.06 Trojan-Spy.Win32.KeyLogger.cor McAfee 5852 2010.01.05 W32/YahLover.worm.gen Microsoft 1.5302 2010.01.06 – NOD32 4747 2010.01.06 Win32/Autoit.FL —————————————————————————————————————————- Additional information File size: 551669 bytes MD5 : d01ef1cc38f805230942d2bb55bfd976 SHA1 : 775bec567155d2ab5ac1d830ba801a243e68312e SHA256: aee6121605f8266079ae0919bbc7ba2b46311c903334d4e8eddb628e9934c515 —————————————————————————————————————————- Installation When the program is executed, it creates […]
More…

Removed: crypt_abuzamnet.info_original.exe

Malware: c:\sand-box\crypt_abuzamnet.info_original.exe Removed: c:\sand-box\crypt_abuzamnet.info_original.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.09 – Kaspersky 7.0.0.125 2010.04.09 Trojan-Downloader.Win32.FraudLoad.gpn Microsoft 1.5605 2010.04.09 – NOD32 5012 2010.04.09 Win32/Agent.ODM —————————————————————————————————————————- Additional information File size: 32768 bytes MD5 : 5e6a2c07e3453c6489957019023b9589 SHA1 : ac14b3e439d1ede0d31764165a10cc27583306c6 SHA256: feb1679b7b77186b5f73fb55aa76815976dc296182cd0a44ee1efda1532c2696 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys […]
More…

Removed: tutocomt1.exe

Malware: d13ef6893db1f45672666793a1fc24d7.exe Removed: C:\WINDOWS\tutocomt1.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.07 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.04.07 – Microsoft 1.5605 2010.04.07 VirTool:Win32/VBInject.gen!BW NOD32 5005 2010.04.06 – —————————————————————————————————————————- Additional information File size: 46619 bytes MD5   : e85bf9cedf157bd6cef3331c94e5c316 SHA1  : 1c1e21bd605246459347d1531a00ff1d4053bc34 SHA256: 14ac7e923e800fe6089840ed4ed799ebbcd59fef8868f15d89d767f6885e39a1 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys and values: ———————————- […]
More…

Malware: C:\sand-box\player033.exe

Malware: C:\sand-box\player033.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.09 Trojan.Generic.3597046 Kaspersky 7.0.0.125 2010.04.09 Trojan-Downloader.Win32.Adload.qlb Microsoft 1.5605 2010.04.08 TrojanDownloader:Win32/Winical.A NOD32 5011 2010.04.08 a variant of Win32/Injector.ALW —————————————————————————————————————————- Additional information File size: 167760 bytes MD5   : f4733e73b41b17f65f97ae4872890533 SHA1  : 45b84cbeafd1c031c2b5e414ce8d3e1bd04053fa SHA256: cb48dd3cf461ba5a5cd262607fffed97ae1636a6d061f38640853b40f3872924 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys and values: […]
More…

Malware: soft2009431.exe

Malware: soft2009431.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.09 – Kaspersky 7.0.0.125 2010.04.09 Trojan.Win32.StartPage.yay Microsoft 1.5605 2010.04.08 – NOD32 5011 2010.04.08 – —————————————————————————————————————————- Additional information File size: 1169191 bytes MD5 : 1cec1c62dc94ada8e62f98121d4dd33e SHA1 : 9e3582458f0b7f316c500e3585cdcb0ce7ac3494 SHA256: 72573aabf7a8ef3bd122e328d38f941d02d2c4847c452c6d335dd6212a5cfa1a —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys and values: […]
More…

Removed: CRYPT_KILL.EXE

Malware: C:\SAND-BOX\CRYPT_KILL.EXE Removed: C:\SAND-BOX\CRYPT_KILL.EXE —————————————————————————————————————————- Classification: <table width=”550″ border=”0″ cellpadding=”0″ cellspacing=”0″ id=”tablaMotores”><tr><td>F-Secure</td><td>9.0.15370.0</td><td>2010.04.08</td><td>-</td></tr><tr><td>Kaspersky</td><td>7.0.0.125</td><td>2010.04.07</td><td>Trojan.Win32.Agent.dqzq</td></tr><td>Microsoft</td><td>1.5605</td><td>2010.04.08</td><td>-</td></tr><tr><td>NOD32</td><td>5008</td><td>2010.04.07</td><td>a variant of Win32/Kryptik.DMM</td></tr></table> —————————————————————————————————————————- Additional information File size: 169984 bytes MD5   : cb6860685c1433395a69ab07af1cc31e SHA1  : 9998f2a4b5c4113eff6e6c1a146a31b799d6a448 SHA256: 4c0dd51bec4a0e44c6251b9c422739fd375ff968eeeb665f5f15076b856647ac —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys and values: ———————————- Values added:1 ———————————- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\nonep: “C:\sand-box\crypt_kill.exe” ———————————- Total changes:1 ———————————- —————————————————————————————————————————- Detected by […]
More…

Removed: diabook.exe (random filename)

Malware: d9e463a586d317e810407f59af76e265.exe Removed: C:\Documents and Settings\Administrator\diabook.exe (random filename) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.01 Gen:Trojan.Chinky.2 Kaspersky 7.0.0.125 2010.04.01 Worm.Win32.VBNA.a McAfee 5937 2010.03.31 W32/VBNA.worm.gen Microsoft 1.5605 2010.03.31 Worm:Win32/Vobfus.H NOD32 4989 2010.03.31 Win32/AutoRun.VB.KD —————————————————————————————————————————- Additional information File size: 81920 bytes MD5   : ec7b150d72bc16199963ea784e73564b SHA1  : edd8cc2c671547a0f00254d27586d711ccdcbe2e SHA256: b9f15b1588cd282f713e3ea7b99582d025ee33b135af14bd4d693d6d2502be42 —————————————————————————————————————————- Installation When the program is executed, it […]
More…

Restored: srsvc.dll

Malware: mtest3.exe Restored: C:\WINDOWS\system32\srsvc.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.08 Gen:Trojan.Heur.bmW@Inuysak Kaspersky 7.0.0.125 2010.04.07 Trojan.Win32.Vilsel.aawv Microsoft 1.5605 2010.04.08 Trojan:Win32/Phyiost.A NOD32 5008 2010.04.07 – —————————————————————————————————————————- Additional information File size: 17408 bytes MD5   : 3247a99e831ff4783bfa54e813990138 SHA1  : a21ea61e100bd1a9b74fd26ca31310c55d5ea13b SHA256: 032eaf743959dda2de7882353143bc76b6d25053dab9fc296675c5e06a665778 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys and values: ———————————- […]
More…

Removed: 6to4v32.dll, rpcmgr.sys

Malware: C:\sand-box\zha.exe Removed: C:\WINDOWS\system32\6to4v32.dll C:\WINDOWS\system32\rpcmgr.sys —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.08 – Kaspersky 7.0.0.125 2010.04.07 – Microsoft 1.5605 2010.04.07 Trojan:Win32/Wimpixo.gen!B NOD32 5008 2010.04.07 – —————————————————————————————————————————- Additional information File size: 51200 bytes MD5   : 5bd6b5b830dc02b33dc01f41c4912263 SHA1  : ba5a66339a784c271ad797c26272b241aebaf9d9 SHA256: 1b4ceeddc8bbecee8949bac26f6d1240404f526646c89f251aefdf80f60a61af —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys and values: […]
More…

Restored: PCI.SYS (The virus chooses a random driver for each infection)

Malware: C:\sand-box\1270595271.exe Restored: C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.08 Trojan.Generic.3596524 Kaspersky 7.0.0.125 2010.04.08 Trojan.Win32.Tdss.baam Microsoft 1.5605 2010.04.08 Trojan:Win32/Alureon.CT NOD32 5009 2010.04.08 a variant of Win32/Kryptik.DNA —————————————————————————————————————————- Additional information File size: 83456 bytes MD5 : da805b061708e572d4c0af275549349d SHA1 : 3fc52e6bfb54f8d766066ba00ceb6a5499f2d527 SHA256: d95e1afacd03f36b74d3601aa3ce109f73bd9a3fc9bfe6822f41d88675c29311 —————————————————————————————————————————- Installation When the program is executed, it creates the […]
More…

Removed: dbf70703.exe (Fake AV – Antimalware Doctor)

Malware: C:\sand-box\dbf70703.exe Removed: C:\sand-box\dbf70703.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.07 Rogue:W32/AntiMalwareDoctor.A Kaspersky 7.0.0.125 2010.04.07 – Microsoft 1.5605 2010.04.07 – NOD32 5006 2010.04.07 a variant of Win32/Adware.AntimalwareDoctor.AA —————————————————————————————————————————- Additional information File size: 963584 bytes MD5   : 900b8cf63014fe98edbe9f2ef189b583 SHA1  : 377434cce7727d94ebebf7ae7369a3937a1cc427 SHA256: fefd7f011243eb10443ad81093510eedc10d73372d340b0a431e4d65bcb16a65 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys […]
More…

Removed: urpext.dll, mplay32xe.exe, urpprot.exe (Fake AV – Your Protection aka Paladin Antivirus)

Malware: C:\sand-box\setup.exe Removed: C:\Program Files\Your Protection\urpext.dll C:\Documents and Settings\Administrator\Local Settings\Temp\mplay32xe.exe C:\Program Files\Your Protection\urpprot.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.07 – Kaspersky 7.0.0.125 2010.04.07 – Microsoft 1.5605 2010.04.07 Trojan:Win32/Rundis.gen!A NOD32 5006 2010.04.07 a variant of Win32/Kryptik.DNA —————————————————————————————————————————- Additional information File size: 258560 bytes MD5   : fea7430f242a187b56e569718ebf9044 SHA1  : 530d10948ad38319315bba943f9bb1298acb4e09 SHA256: f77bcb51fcb6bb0b64177f6f561df6d227310c716993aedc19e64cdcf93ce9a2 —————————————————————————————————————————- Installation When the […]
More…

Removed: zaeixe.exe (random filename)

Malware: b405215c0cc2e2a752b061b13fc8ce89.exe Removed: C:\Documents and Settings\Administrator\zaeixe.exe (random filename) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.01 Gen:Trojan.Chinky.2 Kaspersky 7.0.0.125 2010.04.01 Worm.Win32.VBNA.a McAfee 5937 2010.03.31 W32/VBNA.worm.gen Microsoft 1.5605 2010.03.31 Worm:Win32/Vobfus.H NOD32 4989 2010.03.31 Win32/AutoRun.VB.KD —————————————————————————————————————————- Additional information File size: 81920 bytes MD5 : 5eb4d2278b7fba699eedca778162add3 SHA1 : c30ecd0866792c4ef62ecb692c7754ea4caa0ce0 SHA256: cb8904c0df5e69c9e44e5027c8efea7a07cb675856785db2ed7f4ddd6adbc480 —————————————————————————————————————————- Installation When the program […]
More…

Removed: _VOIDd.sys

Malware: C:\sand-box\install01.exe Removed: C:\WINDOWS\_VOIDmqdsvxercr\_VOIDd.sys —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.07 – Kaspersky 7.0.0.125 2010.04.07 – Microsoft 1.5605 2010.04.07 Trojan:Win32/Alureon.DA NOD32 5006 2010.04.07 a variant of Win32/Kryptik.DNA —————————————————————————————————————————- Additional information File size: 87552 bytes MD5   : 6ad63135b775aa8e16af17be1644231e SHA1  : 2c8fff119a96565414f89c3d28701a3a993c3591 SHA256: 4b1d8ea7e5df548371b60188bdd3043d3a69f5df9e1c6774ef23febc4ed66cb4 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys […]
More…

Removed: msmsgr.exe

Malware: leitenovo.exe Removed: C:\WINDOWS\msmsgr.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.07 DeepScan:Generic.Banker.Delf.5A20FAC5 Kaspersky 7.0.0.125 2010.04.07 Trojan-Banker.Win32.Banker.atcc Microsoft 1.5605 2010.04.07 TrojanDownloader:Win32/Banload.gen!N NOD32 5006 2010.04.07 Win32/Spy.Banker.TNR —————————————————————————————————————————- Additional information File size: 3654144 bytes MD5 : 575f3004e5c8b9325d37b43feb6c9aef SHA1 : 180d16d938f86827000d6840d6e97ae9347e10f9 SHA256: d6b64eb1b9aa1231cf50af1857dcb5ec07dfd35d928165a3d0ac5fac9bc5f1e8 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys […]
More…

Malware: 73_TDL3_24.02.2010_TDL3.27.exe

Malware: C:\sand-box\73_TDL3_24.02.2010_TDL3.27.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.02 Gen:Heur.Krypt.8 Kaspersky 7.0.0.125 2010.03.02 Trojan-GameThief.Win32.Magania.cwgq McAfee 5907 2010.03.01 DNSChanger.at Microsoft 1.5502 2010.03.02 Trojan:Win32/Alureon.CT NOD32 4909 2010.03.02 a variant of Win32/Kryptik.CPZ —————————————————————————————————————————- Additional information File size: 80896 bytes MD5   : 11f1560e6f0d5f85a18dfe99b4be1174 SHA1  : 71e071761c37d94647083508d6c6c413b0ba9246 SHA256: 8115dac8ce2f5e6edf66632c1a47b7e562359838db416079a02efe7abd5e6947 —————————————————————————————————————————- Installation When the program is executed, it creates the following […]
More…

Removed: wlcomn.exe

Malware: dfcd000a5103b6ffd2f632d1f6da84c2.exe Removed: C:\WINDOWS\wlcomn.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.03 Gen:Heur.VB.Krypt.10 Kaspersky 7.0.0.125 2010.04.04 – McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.04.04 – NOD32 4998 2010.04.04 – —————————————————————————————————————————- Additional information File size: 151552 bytes MD5 : 92c468baa9c0339f3b2af37880ea8f43 SHA1 : c724695047b4bd464d83c81713087576ad64cdea SHA256: 24ff57d80fb3879e42564c5d72707926255ec5c2667f5fe73454b0787d19a8ad —————————————————————————————————————————- Installation When the program is executed, it creates […]
More…

Removed: ..\Application Data\ave.exe (Fake Antivirus XP 2010 – malware changes its name every time Windows starts)

Malware: C:\sand-box\9d7f6d5b600546373cafc42bc5a2a670.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.02 Trojan-Spy:W32/Zbot.gen!G Kaspersky 7.0.0.125 2010.04.02 Packed.Win32.Katusha.j McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.04.02 Trojan:Win32/FakeRean NOD32 4995 2010.04.02 a variant of Win32/Kryptik.DFO —————————————————————————————————————————- Additional information File size: 195584 bytes MD5   : b4492af4de0daae0dc91c5c81c3956b6 SHA1  : 968d29a9efe3401dc458d32d9df5fdd0ff9a4a03 SHA256: 70a91b85687d288548a3fab819040f05626c56248fde37fe1d315a1bf5208d3d —————————————————————————————————————————- Installation When the program […]
More…

Removed: fangbian.exe, runfonce.bat (Chinese Game?)

Malware: setup_p3006.exe Removed: C:\program files\·?±a?Ieu°u¶eene?\Fangbian.Exe C:\documents and settings\administrator\start menu\programs\startup\runfonce.Bat —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.31 – Kaspersky 7.0.0.125 2010.03.31 Trojan.Win32.StartPage.xob McAfee 5936 2010.03.30 – Microsoft 1.5605 2010.03.31 – NOD32 4987 2010.03.31 Win32/StartPage.NRN —————————————————————————————————————————- Additional information File size: 1625840 bytes MD5   : 7f109b97f5d370bbcea97caccffad0b1 SHA1  : dfcc4f46fa8b39b9febec4165eb43150a59a32a6 SHA256: 0b99a2457448c6a58ca673c87885fee712ee45214994117fab6ef7ddb10b0e1b —————————————————————————————————————————- Installation When the program is executed, […]
More…

Removed: …\Application Data\bszr.exe

Malware: 89ad2dbdcb5f1ca9f2128c5d093592be.exe Removed: C:\Documents and Settings\Administrator\Application Data\bszr.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.05 – Kaspersky 7.0.0.125 2010.04.05 – Microsoft 1.5605 2010.04.05 – NOD32 5002 2010.04.05 a variant of Win32/Injector.BFT —————————————————————————————————————————- Additional information File size: 111104 bytes MD5   : 3e1099db3a09728e92319ab20b9b6546 SHA1  : 7c240fa83ec37255ec6d2cf6631ec2a54e4a3799 SHA256: 15f1662f7bec3b37acc7a0d1b229fe71f6d57336eabc331a9bfa3f93a63fbeac —————————————————————————————————————————- Installation When the program is executed, it creates the […]
More…

Removed: usrinit.exe

Malware: 6236c627af9e3753d99cf72e84b2768c.exe Removed: C:\WINDOWS\system32\usrinit.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.03 – Kaspersky 7.0.0.125 2010.04.03 Heur.Trojan.Generic McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.04.03 – NOD32 4997 2010.04.03 – —————————————————————————————————————————- Additional information File size: 84992 bytes MD5   : aeabb48b8b39c8f51eb5900f18ce9e91 SHA1  : 28a5422a2286d1f8288c292cc6a6ff5f9d43d7b1 SHA256: b4df3c2e22f5235af79d4d9a3aa8cac2352b65d0e2a46d2ca4349a93b5577979 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry […]
More…

Removed: mssetup.exe

Malware: torpedo_sms.exe Removed: C:\WINDOWS\system32\mssetup.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.31 Gen:Trojan.Heur.PT.cyW@buKF9AaG Kaspersky 7.0.0.125 2010.03.31 Trojan.Win32.Scar.bucy McAfee 5936 2010.03.30 Generic.dx!pcu Microsoft 1.5605 2010.03.31 – NOD32 4986 2010.03.30 probably unknown NewHeur_PE —————————————————————————————————————————- Additional information File size: 45056 bytes MD5   : 6b6d728d546b2809cbd511f63d0e4c1c SHA1  : e3f2a39d63699b1a03d76a9ae060543fe757110f SHA256: 16ad198ee4882349d9a7e32157f34813c13f866448178ca8fdb13daffbe900cf —————————————————————————————————————————- Installation When the program is executed, it creates the […]
More…

Removed: wintmpp.exe

Malware: java.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\wintmpp.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.06 – Kaspersky 7.0.0.125 2010.04.06 – Microsoft 1.5605 2010.04.06 – NOD32 5004 2010.04.06 a variant of Win32/I —————————————————————————————————————————- Additional information File size: 261197 bytes MD5 : 77d5902d5799297801dfec92ee84a2f0 SHA1 : 18ab8f483c278f7643d2cdd8fc7c8684078eedef SHA256: 5b69d9ea2a6e1f17dd40730126ea422246c974b15e734da50d917d8d911a9563 —————————————————————————————————————————- Installation When the program is executed, […]
More…

Removed: …\Application Data\Defender\services.exe, …\Local Settings\Temp\services.exe

Malware: Job_Questionaire.exe Removed: C:\Documents and Settings\Administrator\Application Data\Defender\services.exe C:\Documents and Settings\Administrator\Local Settings\Temp\services.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.06 Trojan.Generic.3185198 Kaspersky 7.0.0.125 2010.04.06 Trojan.Win32.Swisyn.wia Microsoft 1.5605 2010.04.06 Trojan:Win32/Provis!rts NOD32 5003 2010.04.06 probably a variant of Win32/Agent —————————————————————————————————————————- Additional information File size: 409600 bytes MD5 : a531e9485f5a1765d155cf52ea157b6c SHA1 : 9248d85cb44d1e11b280ed844aa247ee786644ed SHA256: 00edbe97c48a1302874c293576d997b876b6ed466400cc627769e7cf540d6ee9 —————————————————————————————————————————- Installation […]
More…

Removed: svihost.exe

Malware: svihost.exe Removed: C:\WINDOWS\system32\svihost.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.05 Backdoor:W32/AutoIt.Z Kaspersky 7.0.0.125 2010.04.05 Backdoor.Win32.AutoIt.z Microsoft 1.5605 2010.04.05 Backdoor:Win32/Layrui.A —————————————————————————————————————————- Additional information File size: 442927 bytes MD5 : 4addc2814e3ef3549f4d4c4c98b3ed24 SHA1 : 8f8345bcd63b0e7d3a0f0bca12174f2db0e86f0d SHA256: f61194e7f4cfebebfce65923e9159d1c62b903052f4c7778346da1886531db36 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys and values: ———————————- Keys […]
More…

Removed: svchost.exe

Malware: C:\sand-box\svchost.exe Removed: C:\sand-box\svchost.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.05 Trojan.Zlob.57627 Kaspersky 7.0.0.125 2010.04.05 Trojan-Spy.Win32.Webmoner.zu Microsoft 1.5605 2010.04.05 – NOD32 5001 2010.04.05 – —————————————————————————————————————————- Additional information File size: 26634 bytes MD5   : ad5f27aa4df95bbcc248805cafe8097d SHA1  : d01acc744714b2e71a987e29c8384e196313f6ea SHA256: 5d919ecd4e190146bcc5225d0a921a97e1e15f7edec082f5912442056c558ff9 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys and values: ———————————- […]
More…

Removed: ZYDXC0209.DLL, autorun.inf, pcidump.sys. Restored: DSOUND.DLL, RPCSS.DLL

Malware: 030.exe Removed: C:\WINDOWS\SYSTEM32\ZYDXC0209.DLL C:\autorun.inf C:\WINDOWS\SYSTEM32\DRIVERS\pcidump.sys Restored: C:\WINDOWS\SYSTEM32\DSOUND.DLL C:\WINDOWS\SYSTEM32\RPCSS.DLL —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.24 Trojan.Generic.3115629 Kaspersky 7.0.0.125 2010.03.24 Trojan-Downloader.Win32.Geral.noj McAfee 5929 2010.03.23 – Microsoft 1.5605 2010.03.24 TrojanDropper:Win32/Dogkild.A NOD32 4969 2010.03.23 a variant of Win32/AutoRun.KillAV.N —————————————————————————————————————————- Additional information File size: 32256 bytes MD5   : 7810b652c7244875b4d99bd9288aee3c SHA1  : c63bb1a1e90332a6245f5420efc3c653894d36f6 SHA256: a9038cfced406ca2db41dd3e87e57a056dbda8481e92c299944dffcab4bb18ac —————————————————————————————————————————- Installation When the […]
More…

Removed: winupgro.exe, wfsintwq.sys

Malware: BCU.EXE Removed: C:\Documents and Settings\Administrator\Application Data\drivers\winupgro.exe C:\WINDOWS\system32\wfsintwq.sys —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.03 MemScan:Trojan.Downloader.Bagle.MH Kaspersky 7.0.0.125 2010.04.04 – McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.04.03 – NOD32 4997 2010.04.03 – —————————————————————————————————————————- Additional information File size: 1054720 bytes MD5   : 097162fb2aa3415818d106dd7b0389c3 SHA1  : c9e03d1b6d302628090ee9ba4c0665ea7771c318 SHA256: d5fc7171cbdc6c0ac21c101c60faf6023af7e9d792912ee15a52d81e80ba850d —————————————————————————————————————————- Installation When the program is executed, it […]
More…

Removed: C:\WINDOWS\ssystem32\svchost.exe

Malware: a.exe Removed: C:\WINDOWS\ssystem32\svchost.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.31 – Kaspersky 7.0.0.125 2010.03.31 Trojan.Win32.VBok.iu McAfee 5936 2010.03.30 BackDoor-CEP.svr Microsoft 1.5605 2010.03.31 VirTool:Win32/VBInject NOD32 4988 2010.03.31 Win32/Bifrose.NFJ —————————————————————————————————————————- Additional information File size: 163853 bytes MD5   : 1a6b50ce5bf5c3596b67ba067e196d06 SHA1  : 9cdbb7a488c9191e18a7e07715b7542bed9ffb9d SHA256: 214a8f82d31d13001d0a2ef611e561c859444716bf4318afd9ce356cbac88ee6 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry […]
More…

Removed: 432010232231.dll(random filname)

Malware: file.exe Removed: C:\WINDOWS\system32\432010232231.dll(random filname) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.02 Trojan.Spy.Banker.AAOE Kaspersky 7.0.0.125 2010.04.03 Trojan-PSW.Win32.Small.lx McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.04.02 TrojanSpy:Win32/Delf.BT NOD32 4995 2010.04.02 – —————————————————————————————————————————- Additional information File size: 47104 bytes MD5 : f9c85379d2f41219d0a9a74eaa40b9b0 SHA1 : 7ad5846a99019288374036c03d4d380255bb6085 SHA256: 58f2a1dab786c6d8a1e4450e15e7a93cbccd43eb8ffc6ec8abd043c43fca4b62 —————————————————————————————————————————- Installation When the program is executed, it […]
More…

Removed: WinHelper.exe

Malware: ok.exe Removed: C:\WINDOWS\system32\WinHelper.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.29 – Kaspersky 7.0.0.125 2010.03.29 – McAfee 5934 2010.03.28 BackDoor-CEB Microsoft 1.5605 2010.03.29 Trojan:Win32/SystemHijack.gen NOD32 4982 2010.03.29 a variant of Win32/Agent.NWM —————————————————————————————————————————- Additional information File size: 39936 bytes MD5 : 4de2ef81e9f571da6d972de55857a7f5 SHA1 : d65d9371466b9a0c689e8ef5642e0a2cd8b7236c SHA256: 5767b51e60889179ace3006602c806cc15bc7c4c846b0e859c17498b18676c4c —————————————————————————————————————————- Installation When the program is […]
More…

Removed: vsbntlo.exe

Malware: pr3xy.exe Removed: C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.02 Trojan.Generic.3469355 Kaspersky 7.0.0.125 2010.04.03 Trojan.Win32.Buzus.dhiv McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.04.03 Trojan:Win32/Remhead NOD32 4995 2010.04.02 a variant of Win32/Injector.AXU —————————————————————————————————————————- Additional information File size: 114695 bytes MD5 : 928bbb8e916e9ff65d27faa6d3776dcc SHA1 : 491aefc4a7e0c60ef170481b89b3d187095245b4 SHA256: b6125ed99d7be91437ba1c2bd0776baae120d5d009d6101d19428458a452ea72 —————————————————————————————————————————- Installation When the program is […]
More…

Removed: lc1102.exe

Malware: c:\sand-box\lc1102.exe Removed: c:\sand-box\lc1102.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.29 Trojan.Generic.2799217 Kaspersky 7.0.0.125 2010.03.29 Trojan-Downloader.Win32.Agent.curg McAfee 5934 2010.03.28 Generic.dx!fgy Microsoft 1.5605 2010.03.29 TrojanDownloader:Win32/Troxen!rts NOD32 4981 2010.03.29 probably a variant of Win32/Genetik —————————————————————————————————————————- Additional information File size: 156928 bytes MD5 : 432fb48da46fe7bd9dae24804d950254 SHA1 : 47a08b006aead30155925bd04af54c43eb1717c0 SHA256: c98cb0233b56a6c566241c8c4e1affc20c7ce92eca8ec8820348963b6ea86b6e —————————————————————————————————————————- Installation When the program […]
More…

Removed: server.exe

Malware: qqqqq.exe Removed: C:\Program Files\Bifrost\server.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.05 Trojan.Generic.2935507 Kaspersky 7.0.0.125 2010.03.05 Trojan.Win32.Refroso.acsp McAfee 5911 2010.03.05 Generic VB.i Microsoft 1.5502 2010.03.06 VirTool:Win32/VBInject.gen!AN NOD32 4919 2010.03.05 a variant of Win32/Injector.ARC —————————————————————————————————————————- Additional information File size: 87058 bytes MD5 : 322bb724462ee7a52dc9c6c96aab9e9e SHA1 : ad96d65b084746ec45eccc55816eb7f9221abb74 SHA256: 8454299a2c9e12a6f7e72779229efcd922dc492d4311dfe9d0edaf8dfb16af09 —————————————————————————————————————————- Installation When the […]
More…

Removed: mspdb37.dll

Malware: C:\sand-box\us.exe Removed: C:\Documents and Settings\All Users\Application Data\Microsoft\Windows\mspdb37.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.31 Trojan-Spy:W32/Agent.DIQI Kaspersky 7.0.0.125 2010.03.31 Trojan-Dropper.Win32.Agent.buto McAfee 5936 2010.03.30 Generic PWS.y!cgo Microsoft 1.5605 2010.03.31 TrojanSpy:Win32/Sodast.A NOD32 4986 2010.03.30 a variant of Win32/Kryptik.DIN —————————————————————————————————————————- Additional information File size: 111616 bytes MD5 : e939e37c68188b52a6e14cc4f831ddd0 SHA1 : 9159676b6c61363197de5539c6c12bc7caffc04f SHA256: 94e2ffb52e90a40eefc36e88afdf1c7434e6252c593abf3e49c61ae87a4eee07 —————————————————————————————————————————- […]
More…

Removed: msvmcls64.exe

Malware: sm.exe Removed: C:\WINDOWS\system32\msvmcls64.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.24 Trojan.Generic.3469355 Kaspersky 7.0.0.125 2010.03.24 Trojan.Win32.Buzus.dhiv McAfee 5929 2010.03.23 Generic.dx!olp Microsoft 1.5605 2010.03.24 Spammer:Win32/Tedroo.A NOD32 4971 2010.03.24 a variant of Win32/Injector.AXU —————————————————————————————————————————- Additional information File size: 331783 bytes MD5 : bd7b20ec5e9bfc426dad7fed0a2e7613 SHA1 : f85f02ac6dbed3471aa859105aebee0c01276be6 SHA256: 1dc4ad40b983dbbb1d819dcf1c8785be4c1407e83e91acd40942b02a4bf6cdcc —————————————————————————————————————————- Installation When the program is […]
More…

Removed: setup_1904.exe

Malware: C:\sand-box\setup_1904.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\setup_1904.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.31 Rogue:W32/SecurityGuard.A Kaspersky 7.0.0.125 2010.03.31 Trojan.Win32.Tdss.azpf McAfee 5936 2010.03.30 DNSChanger.bf Microsoft 1.5605 2010.03.31 TrojanDownloader:Win32/FakeVimes NOD32 4986 2010.03.30 a variant of Win32/Kryptik.DHT —————————————————————————————————————————- Additional information File size: 201728 bytes MD5 : 6cb447d416e868f5840af78bb2d9fd30 SHA1 : 1167d155ffbb455353659f4fc30e162c876c0685 SHA256: d9ce036f6b25d812c16c3653a6b80d539491bfc30415e265e0f7f3d4752cba82 —————————————————————————————————————————- Installation When […]
More…

Removed: AtapiDrv.sys

Malware: C:\sand-box\load.exe Removed: C:\WINDOWS\system32\drivers\AtapiDrv.sys —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.01 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.04.01 Trojan.Win32.Tdss.azvo McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.03.31 – NOD32 4992 2010.04.01 a variant of Win32/Kryptik.DLH —————————————————————————————————————————- Additional information File size: 69120 bytes MD5 : 33157597db16fdfb9e5b47455bdd7a79 SHA1 : 5094366b2b31e81a0669148aa6df71d64beda573 SHA256: ab980e74feb1eb4ca9c60d7b4a7781f6e4c4cbfe0ab45124aaa479634a5042a9 —————————————————————————————————————————- Installation When the program is […]
More…

Removed: prqy.fko

Malware: C:\sand-box\s5.exe Removed: C:\WINDOWS\system32\prqy.fko —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.29 – Kaspersky 7.0.0.125 2010.03.29 Trojan.Win32.Sasfis.akmg McAfee 5935 2010.03.29 – Microsoft 1.5605 2010.03.29 – NOD32 4983 2010.03.29 Win32/Oficla.FI —————————————————————————————————————————- Additional information File size: 23040 bytes MD5 : 4b0eb6b90c8dbeeaf5a870b7cdf77d00 SHA1 : 6ac75e12ba5c271816ac08b95ec33927deb05ade SHA256: 9a62ddb2edb1ab6a613748552cbd98b50b8e3005862e98486316e2e4f9f5a1c7 —————————————————————————————————————————- Installation When the program is executed, it creates […]
More…

Removed: lywc.aoo

Malware: up.exe Removed: C:\WINDOWS\system32\lywc.aoo —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.28 Trojan.Generic.KD.4775 Kaspersky 7.0.0.125 2010.03.28 Trojan.Win32.Sasfis.ajhr McAfee 5933 2010.03.27 – Microsoft 1.5605 2010.03.28 – NOD32 4978 2010.03.26 a variant of Win32/Kryptik.DBO —————————————————————————————————————————- Additional information File size: 22528 bytes MD5 : e61c265fd436f79dbacfe94ed2bc4ddf SHA1 : ff491caba6d389556b6e885cd4d4cd9207bff847 SHA256: 15c6cbc2f60b1e16a12e8fd22c0e1d4c0ba50457e28bdfb60e622223c4e15863 —————————————————————————————————————————- Installation When the program is […]
More…

Removed: autorun.inf, NOOJI.SYS (random filename)

Malware: d386a7b7eae8219b30716aeac5c03c54.exe Removed: C:\autorun.inf C:\WINDOWS\SYSTEM32\DRIVERS\NOOJI.SYS (random filename) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.29 Win32.Sality.N Kaspersky 7.0.0.125 2010.03.29 P2P-Worm.Win32.Bacteraloh.h McAfee 5934 2010.03.28 W32/Sality.gen Microsoft 1.5605 2010.03.28 Virus:Win32/Sality.T NOD32 4980 2010.03.28 Win32/Sality.NAM —————————————————————————————————————————- Additional information File size: 155648 bytes MD5 : bd023ab9eb3fddb7182f3bfbbcdfcafe SHA1 : 9a7364b297841c5883dda227681f321d44fb0b4e SHA256: 97200d75131bda00201ebf0af3978652f3f51d01e7c6d5864028a4e820474c75 —————————————————————————————————————————- Installation When the program is […]
More…

Removed: evennsta.dll (random filename)

Malware: C:\sand-box\ch7.exe Removed: C:\WINDOWS\system32\evennsta.dll (random filename) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.29 – Kaspersky 7.0.0.125 2010.03.29 – McAfee 5934 2010.03.28 – Microsoft 1.5605 2010.03.29 – NOD32 4982 2010.03.29 Win32/PSW.Papras.BG —————————————————————————————————————————- Additional information File size: 108544 bytes MD5   : b4f734d5e67d073e6ffcbe11f2de3b74 SHA1  : 5cd85f91e9c81b1d085371c1752985110e38b772 SHA256: cae5b055515b5e80744d9f327e2e9159a390c1621651a3f138ff5fa6ad2c0305 —————————————————————————————————————————- Installation When the program is executed, it creates the […]
More…

Removed: iidqd.lib

Malware: ztbaomu.exe Removed: C:\Program Files\NetMeeting\iidqd.lib —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.01 – Kaspersky 7.0.0.125 2010.04.01 Trojan-PSW.Win32.Bjlog.foh McAfee 5937 2010.03.31 BackDoor-EMA Microsoft 1.5605 2010.03.31 Backdoor:Win32/Zegost.B NOD32 4990 2010.04.01 Win32/Redosdru.CO —————————————————————————————————————————- Additional information File size: 823364 bytes MD5   : 9336fe8542ed11dc3f4cfa46caf9d330 SHA1  : ab5048189881ca96687edd6be679d4394dc13400 SHA256: fcdc610dceed348b1b45ce8ec54a173485a2ac826f57a19f1977322836bbbc24 —————————————————————————————————————————- Installation When the program is executed, it creates the following […]
More…

Removed: cbhr.uco

Malware: C:\sand-box\000.exe Removed: C:\WINDOWS\system32\cbhr.uco —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.31 – Kaspersky 7.0.0.125 2010.03.31 Trojan.Win32.Sasfis.akgp McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.03.31 Trojan:Win32/Meredrop NOD32 4988 2010.03.31 Win32/Oficla.FJ —————————————————————————————————————————- Additional information File size: 20480 bytes MD5   : a770d6d6f680c42e75473ca00880ca48 SHA1  : 1c884280d13db3a23639582c2dd081c3e203df83 SHA256: d5bc3d08bca0113e8450d6c18b75314c6cd250b24486161de42bc98441a0b069 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry […]
More…

Removed: jiji0.exe, clearIE.exe

Malware: cIE.exe Removed: C:\WINDOWS\system32\jiji0.exe C:\clearIE.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.01 – Kaspersky 7.0.0.125 2010.04.01 Trojan-Downloader.Win32.Apher.gsl McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.03.31 – NOD32 4990 2010.04.01 Win32/Agent.NOV —————————————————————————————————————————- Additional information File size: 615571 bytes MD5 : fabcdf9d4a45d3decc1bc65f1af91b94 SHA1 : 9a290bb7fd23dc8e7bdaa3b0d97e71507324c91a SHA256: 5b7fdb54976b5b8047a9d40a2a3a8a291ad5c8d83b8633c7f968e37eb9862be8 —————————————————————————————————————————- Installation When the program is executed, it […]
More…

Removed: winrev.exe

Malware: Removed: C:\Documents and Settings\Administrator\Application Data\windowx58h\winrev.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.26 – Kaspersky 7.0.0.125 2010.03.26 Trojan-Dropper.Win32.VB.alxr McAfee 5931 2010.03.25 – Microsoft 1.5605 2010.03.26 – NOD32 4976 2010.03.26 Win32/PSW.VB.NER —————————————————————————————————————————- Additional information File size: 151564 bytes MD5 : b2df5e041318f810b8b81397975e52e4 SHA1 : 11665366628eb31a304b19067a7e78387a630f79 SHA256: a59a439157b04369a6a4e8558292cc515bf29d62522dc34c8e70902aac4571d0 —————————————————————————————————————————- Installation When the program is executed, […]
More…

Restored: ATAPI.SYS

Malware: C:\sand-box\browser-player.exe Restored: C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.26 Trojan.TDss.ABP Kaspersky 7.0.0.125 2010.03.26 Trojan.Win32.Tdss.ayhi McAfee 5931 2010.03.25 DNSChanger.as Microsoft 1.5605 2010.03.26 Trojan:Win32/Alureon.CT NOD32 4975 2010.03.25 a variant of Win32/Kryptik.DDG —————————————————————————————————————————- Additional information File size: 82432 bytes MD5   : c5d16aa2b08f1cc67df20011fc37d19f SHA1  : d1313bb9c67688bd093daf2d6a6160a35dd289eb SHA256: 5cd8b34b1dc1d486b9a31193aff9a209d7f91863a39312ea59e738d13715a90c —————————————————————————————————————————- Installation When the program is executed, it creates […]
More…

Removed: One.sys, kav.exe

Malware: C:\sand-box\aaa.exe Removed: C:\WINDOWS\system32\drivers\One.sys C:\WINDOWS\system32\kav.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.27 – Kaspersky 7.0.0.125 2010.03.27 Backdoor.Win32.Nihem.aa McAfee 5932 2010.03.26 Downloader-CGR Microsoft 1.5605 2010.03.27 TrojanDownloader:Win32/Dogrobot.D NOD32 4978 2010.03.26 Win32/AntiAV.NEY —————————————————————————————————————————- Additional information File size: 35328 bytes MD5 : 24de2260548f5892398f0b0c14e57f45 SHA1 : f515591fcc750c90d5e6b81d742720ddbdd7b234 SHA256: 5939305005a3b724863e7fc54b83cbe1a30f60d5acb28bf682acc5b303a38bee —————————————————————————————————————————- Installation When the program is executed, it […]
More…

Removed: ashxPaFtu.dll , a2ne6iefh.exe (random filnames) (Fake AV – Virus Protector)

Malware: flash_player_10.35.exe Removed: c:\WINDOWS\system32\ashxPaFtu.dll (random filnames) C:\WINDOWS\system32\a2ne6iefh.exe (random filnames) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.28 – Kaspersky 7.0.0.125 2010.03.28 – McAfee 5933 2010.03.27 – Microsoft 1.5605 2010.03.28 – NOD32 4978 2010.03.26 – —————————————————————————————————————————- Additional information File size: 74113 bytes MD5 : 69dfc0f1ab8ccf2f59af86f22e70f79e SHA1 : fd9252bc788ccb95f98267179fe445e8b0cefdf9 SHA256: 2707b61f3b97aa78107f00e50da11079500df446bddd6d71a262267a6e6bddc0 —————————————————————————————————————————- Installation When the […]
More…

Removed: spoolsv.exe

Malware: hallmark-card.exe Removed: C:\WINDOWS\Temp\spoolsv\spoolsv.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.30 Backdoor.Zapchast.PF Kaspersky 7.0.0.125 2010.03.30 Backdoor.IRC.Zapchast.zwrc McAfee 5935 2010.03.29 potentially unwanted program IRC/Client Microsoft 1.5605 2010.03.30 Backdoor:Win32/IRCFlood NOD32 4984 2010.03.30 REG/RunKeys.NAA —————————————————————————————————————————- Additional information File size: 933588 bytes MD5 : a467b04cfabc4fd2bf9e8a39c5d8ff3d SHA1 : c89a35f99768a2431b0ce3145b159c8c8db9f7f1 SHA256: 107e0fe14c686942fbd748e1d22cdacd82745d30bfb855ceaf465aeba8d3cbf3 —————————————————————————————————————————- Installation When the program is […]
More…

Restored: ATAPI.SYS

Malware: C:\sand-box\setup.exe Restored: C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.30 – Kaspersky 7.0.0.125 2010.03.30 Trojan-Dropper.Win32.TDSS.ah McAfee 5935 2010.03.29 – Microsoft 1.5605 2010.03.30 – NOD32 4983 2010.03.29 – —————————————————————————————————————————- Additional information File size: 158208 bytes MD5 : 97924335f34b0e8a0a1ffe4f00db5398 SHA1 : 33e2d222f55750d5c7c8649c7a3754df2b8db433 SHA256: 8733c2b617f23c4ef829521af3300a7f8d330ef86c11d5eb0041cfeee320b18d —————————————————————————————————————————- Installation When the program is executed, it creates […]
More…

Removed: rxms.pio

Malware: C:\sand-box\file.exe Removed: C:\WINDOWS\system32\rxms.pio —————————————————————————————————————————- Classification: 2 Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.26 – Kaspersky 7.0.0.125 2010.03.25 – McAfee 5931 2010.03.25 – Microsoft 1.5605 2010.03.26 TrojanDropper:Win32/Oficla.G NOD32 4975 2010.03.25 a variant of Win32/Kryptik.DHG —————————————————————————————————————————- Additional information File size: 59392 bytes MD5 : 0ef93cd209526a80e73b08820fd6d7b2 SHA1 : f008b60528aa39615bf6f1caa41a559686a46259 SHA256: 63f1421b7af2c5aefbdd5819ced8e13173eeeffc3097b6acb084850cc67e22d3 —————————————————————————————————————————- Installation When the program […]
More…

Removed: services.exe, msbyylfy.dll (random filname)

Malware: C:\sand-box\erdown.exe Removed: C:\WINDOWS\fonts\services.exe C:\WINDOWS\system32\msbyylfy.dll (random filname) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.27 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.03.27 Trojan-Downloader.Win32.Genome.apng McAfee 5932 2010.03.26 – Microsoft 1.5605 2010.03.27 – NOD32 4978 2010.03.26 a variant of Win32/PSW.WOW.NOP —————————————————————————————————————————- Additional information File size: 18432 bytes MD5   : 4a7bbd7e0de0c56704d034722182aec4 SHA1  : 920bfe65bcf08399ec4a6b851b91760e26669bfd SHA256: 72c7dc5d668c254451c619aa925cea61a48deae46c59d33e5f82135dab884245 —————————————————————————————————————————- Installation When the program is […]
More…

Removed: iasdewqx.exe

Malware: antirap.exe Removed: C:\WINDOWS\system32\iasdewqx.exe (Random file name each time you start Windows.) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.27 Gen:Trojan.Heur.Hype.lq0@aeouoFfi Kaspersky 7.0.0.125 2010.03.27 Trojan-Downloader.Win32.Injecter.dpr McAfee 5933 2010.03.27 Generic Downloader.x!ddi Microsoft 1.5605 2010.03.27 Trojan:Win32/Malagent NOD32 4978 2010.03.26 Win32/Agent.QVQ —————————————————————————————————————————- Additional information File size: 195584 bytes MD5   : 59ea3dac43856ce6f3946f3eb871ab8a SHA1  : 4df81ff5a96cf7f72a93a35a74a96b6fb550be34 SHA256: f9c2622342e3d1eca122da6a9b4bbb82458bf0458316d6b61b70de3205c9d013 —————————————————————————————————————————- Installation When […]
More…

Removed: adsnwv.exe (random filename)

Malware: update.exe Removed: C:\WINDOWS\system32\adsnwv.exe (random filename) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.27 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.03.27 Backdoor.Win32.IRCNite.gk McAfee 5932 2010.03.26 – Microsoft 1.5605 2010.03.26 Trojan:Win32/Meredrop NOD32 4978 2010.03.26 Win32/IRCBot.NBC —————————————————————————————————————————- Additional information File size: 63488 bytes MD5 : 10088d837220b21ddfc4da518b088147 SHA1 : ad268e64172bff50fadef4dc95e2a7f92edfede7 SHA256: 29d08d1443aa24d50102b47f51abe60a9e3625345742426f85dcc7389b6393ab —————————————————————————————————————————- Installation When the program is executed, […]
More…

Removed: ACTIVE.EXE

Malware: C:\SAND-BOX\ACTIVE.EXE Removed: C:\SAND-BOX\ACTIVE.EXE —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.27 Backdoor:W32/PoisonIvy.gen!A Kaspersky 7.0.0.125 2010.03.27 Backdoor.Win32.Poison.pg McAfee 5932 2010.03.26 BackDoor-DSS.gen.a Microsoft 1.5605 2010.03.27 Backdoor:Win32/Poisonivy.H NOD32 4978 2010.03.26 Win32/Poison.NAE —————————————————————————————————————————- Additional information File size: 9728 bytes MD5 : 56a9737e9205a3af1521dfda6fbb7396 SHA1 : ea89ff1a542c1f126e350f91eee97965d51120d3 SHA256: a105d75c1fa14cb7c66d398f7ee27a3507e7aaceabbd827404774de02d037b97 —————————————————————————————————————————- Installation When the program is executed, it creates […]
More…

Removed: qtplugin.exe

Malware: paints10.exe Removed: C:\WINDOWS\system32\qtplugin.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.25 – Kaspersky 7.0.0.125 2010.03.25 – McAfee 5930 2010.03.24 – Microsoft 1.5605 2010.03.25 Trojan:Win32/Meredrop NOD32 4973 2010.03.25 Win32/PSW.Delf.NWB —————————————————————————————————————————- Additional information File size: 604160 bytes MD5 : 3e17bde3ac4c7d519159f95f018573a4 SHA1 : a15c0ba7310bc7495c0192cb3286e5206aabfbea SHA256: 5e1698cb96e6156155f660c6f74d659b33c8a73135e4c272fd05e25b1ccf42e6 —————————————————————————————————————————- Installation When the program is executed, it creates […]
More…

Removed: MsMxEng.exe

Malware: drweb32.exe Removed: C:\RECYCLER\S-1-5-21-0253694876-1249060442-867131471-1179\MsMxEng.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.01 – Kaspersky 7.0.0.125 2010.02.01 – McAfee 5878 2010.01.31 – Microsoft 1.5406 2010.02.01 – NOD32 4823 2010.02.01 a variant of Win32/Injector.ATV —————————————————————————————————————————- Additional information File size: 251911 bytes MD5 : 8debd0f8b55595f4890ada9e9e2e3708 SHA1 : f08b75beca3cee036e68e66521913f4f9e1dcb31 SHA256: bd9cf298ee3321d305c68d34a937d10343b10b583e5180a0fa87532e4933fd55 —————————————————————————————————————————- Installation When the program is […]
More…

Removed: rpopv.exe (filename randomly)

Malware: C:\sand-box\admin.exe Removed: C:\WINDOWS\system32\rpopv.exe (filename randomly) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.26 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.03.26 Trojan.Win32.Pincav.xux McAfee 5932 2010.03.26 PWS-Mmorpg!ne Microsoft 1.5605 2010.03.26 PWS:Win32/Magania.gen NOD32 4978 2010.03.26 Win32/PSW.Gamania.NCK —————————————————————————————————————————- Additional information File size: 53248 bytes MD5 : b302673f5c7cb13a6dc3dbaa1e26104d SHA1 : 25b305f26164341672edd48a60927f11f3f85d92 SHA256: cee9c434a95b4080b6d51fe1cdb45b8022f93bba3ebccbfef52ac1b22e1d871b —————————————————————————————————————————- Installation When the program is executed, […]
More…

Removed: cwsq.sys, RtPW.dll (filename randomly)

Malware: image.jpg.exe Removed: C:\WINDOWS\system32\drivers\cwsq.sys C:\WINDOWS\system32\RtPW.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.25 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.03.25 – McAfee 5930 2010.03.24 – Microsoft 1.5605 2010.03.25 Backdoor:Win32/Koutodoor.C NOD32 4972 2010.03.24 – —————————————————————————————————————————- Additional information File size: 70656 bytes MD5 : 1950e36840527f3c089b0a766aaa27f0 SHA1 : 48b3c2011295009c20edc9ce56bf7ff2a7c34f08 SHA256: 9a6db096faa696cc4020e428697ee380de73828c773f29b49f48b5664ffbf913 —————————————————————————————————————————- Installation When the program is executed, it […]
More…

Removed: webserver.exe

Malware: 89f1d5f0030856ce231817b895eda362.exe Removed: C:\Program Files\webserver\webserver.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.27 Gen:Trojan.Heur.GZ.amGfbu9frXn Kaspersky 7.0.0.125 2010.03.26 P2P-Worm.Win32.Palevo.xfo McAfee 5932 2010.03.26 W32/Koobface.worm.gen.e Microsoft 1.5605 2010.03.26 Trojan:Win32/Koobface.gen!B NOD32 4978 2010.03.26 Win32/TrojanProxy.Small.NEB —————————————————————————————————————————- Additional information File size: 15360 bytes MD5   : d5db0c2908d025c792231901deeacf42 SHA1  : a945753725b8d8f7484edb735f54cc79e1ef79ed SHA256: 1108276c9773c90d617a96603981624160d8948e6992038eca7826f7700dc397 —————————————————————————————————————————- Installation When the program is executed, it creates the following […]
More…

Removed: bill104.exe

Malware: C:\sand-box\b0bef6526619d239f4ebf436adf69e24.exe Removed: C:\WINDOWS\bill104.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.27 – Kaspersky 7.0.0.125 2010.03.26 Net-Worm.Win32.Koobface.fyn McAfee 5932 2010.03.26 Generic Spy.e Microsoft 1.5605 2010.03.26 VirTool:Win32/VBInject.gen!DG NOD32 4978 2010.03.26 Win32/Koobface.NCT —————————————————————————————————————————- Additional information File size: 71680 bytes MD5 : 7aab063c2b270f335ff91b288530bad0 SHA1 : 6e0a25c702b2e37407fbb8e4cd41ed7a46f58f49 SHA256: d55a9f0b78710f44079768b618a11a05cd71bec61d7a9d3117aa1dbb2a37196b —————————————————————————————————————————- Installation When the program is executed, it […]
More…

Removed: windump.exe, Svechost.exe

Malware: C:\sand-box\load.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\windump.exe C:\WINDOWS\system32\Svechost.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.25 Gen:Trojan.Heur.Hype.kq0@auFXULmi Kaspersky 7.0.0.125 2010.03.25 Trojan.Win32.Scar.bxvh McAfee 5930 2010.03.24 – Microsoft 1.5605 2010.03.24 – NOD32 4972 2010.03.24 a variant of Win32/Injector.BDW —————————————————————————————————————————- Additional information File size: 177152 bytes MD5 : a04da9805c49fae7b437210201771b14 SHA1 : ca606d7c8eed33f50eadf3bb0b578eef58d955a4 SHA256: e042f3896f9ca655808a6b716561b3f6bd4f910bede1ca9a6446343da6772c43 —————————————————————————————————————————- Installation […]
More…

Removed: intro_hiding.dll

Malware: load.exe Removed: C:\WINDOWS\system32\intro_hiding.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.25 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.03.25 Trojan.Win32.Agent2.cpwr McAfee 5931 2010.03.25 – Microsoft 1.5605 2010.03.25 Trojan:Win32/Malagent NOD32 4975 2010.03.25 Win32/Delf.NQE —————————————————————————————————————————- Additional information File size: 58880 bytes MD5 : aff3a3375747eb984f6e3bef1082aa6c SHA1 : 53f0e34bf4c5ce74e66c4a8b3084b36ccb924d93 SHA256: e95c2048c923b66cd98d078843bd1e47c25ec021a706093cf89a99fb7d94a6f6 —————————————————————————————————————————- Installation When the program is executed, it creates […]
More…

Removed: wmfcgr.exe (filename randomly)

Malware: e5ad9814df907e9e1d1490b9d23bf456.exe Removed: C:\RECYCLER\S-1-5-21-8755532886-2138942026-864167170-2676\wmfcgr.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.26 – Kaspersky 7.0.0.125 2010.03.26 P2P-Worm.Win32.Palevo.ymc McAfee 5931 2010.03.25 Generic.dx!pof Microsoft 1.5605 2010.03.26 VirTool:Win32/VBInject.DN NOD32 4976 2010.03.26 a variant of Win32/Injector.BBZ —————————————————————————————————————————- Additional information File size: 200704 bytes MD5 : 07cbf08f500096cd7698c9f5fa44edad SHA1 : 98ae32d9abff6b629d4933f60cd2953e12a43204 SHA256: 5d91324e32124befa690a611c9ed2c609c5e0785c6efbb185e62f9fc05df21f7 —————————————————————————————————————————- Installation When the program is […]
More…

Removed: ihnqp.url (filename randomly)

Malware: tbe.exe Removed: C:\Documents and Settings\All Users\ihnqp.url (filename randomly) —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.24 Dropped:Packer.Malware.NSAnti.1 Kaspersky 7.0.0.125 2010.03.24 Trojan.Win32.Chifrax.qg McAfee 5930 2010.03.24 Generic.dx!paz Microsoft 1.5605 2010.03.24 Trojan:Win32/Chifrax.A NOD32 4971 2010.03.24 Win32/Redosdru.CN —————————————————————————————————————————- Additional information File size: 166866 bytes MD5 : 02bf9f780a315067d1de4bf84c30a94f SHA1 : e9244d945dd97e02bc7991250815d2548c7cd019 SHA256: eb80437dade04ef2c2e8a17cc2d0e8ce08d4b4a0cc544de97198bb27f439e36b —————————————————————————————————————————- Installation When the […]
More…

Removed: At1.job, memm.exe (filename randomly)

Malware: pics.exe Removed: C:\WINDOWS\system32\memm.exe C:\WINDOWS\Tasks\At1.job —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.25 – Kaspersky 7.0.0.125 2010.03.25 Trojan-Dropper.Win32.Mudrop.hfa McAfee 5931 2010.03.25 Generic Dropper!ctp Microsoft 1.5605 2010.03.25 – NOD32 4974 2010.03.25 Win32/TrojanDropper.Agent.OQK —————————————————————————————————————————- Additional information File size: 227840 bytes MD5 : bd640fac06a1c1984124b3dfc1830b77 SHA1 : 64f628e0a085e1cc7786a58bc202b0b7efc95bf5 SHA256: 7f5a7e5bce8c94d2af9ad022d8367bd88362fb37dc03406c8933056135c60b68 —————————————————————————————————————————- Installation When the program is executed, […]
More…

Removed: _VOIDD.SYS, USREXT.DLL, FONTVIEWXP.EXE, USRPROT.EXE (Fake AV – User Protection, aka Antivirus XP 2010)

Malware: C:\sand-box\adobeflashplayerv10.0.45.2.exe Removed: C:\WINDOWS\_VOIDEQQHXRNIXR\_VOIDD.SYS C:\PROGRA~1\USERPR~1\USREXT.DLL C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\FONTVIEWXP.EXE C:\PROGRAM FILES\USER PROTECTION\USRPROT.EXE —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.25 Trojan-Downloader:W32/Agent.OBP Kaspersky 7.0.0.125 2010.03.25 – McAfee 5930 2010.03.24 – Microsoft 1.5605 2010.03.25 – NOD32 4972 2010.03.24 Win32/TrojanDownloader.FakeAlert.AVO —————————————————————————————————————————- Additional information File size: 20992 bytes MD5 : 9e446c421b0e8b121069836936d898a9 SHA1 : 2440e2a763a22017768d827a441bf59a3ee35d12 SHA256: abf966786b2151ce463d085c25645a75f94041242004882ae2b3f400d61f64b6 —————————————————————————————————————————- Installation When the […]
More…

Removed: lsass.exe, odbnsy.exe, sms.exe, svc.exe, svw.exe

Malware: 55ttr.exe Removed: C:\WINDOWS\lsass.exe C:\WINDOWS\odbnsy.exe C:\WINDOWS\sms.exe C:\WINDOWS\svc.exe C:\WINDOWS\svw.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.24 – Kaspersky 7.0.0.125 2010.03.24 – McAfee 5930 2010.03.24 – Microsoft 1.5605 2010.03.24 TrojanDropper:Win32/Microjoin.gen!B NOD32 4971 2010.03.24 a variant of Win32/Kryptik.DFO —————————————————————————————————————————- Additional information File size: 2015744 bytes MD5 : 769c38d76e3e99a0fbf4ea58b071b371 SHA1 : 5e9c127892ccfc6df9aabd0e739749382fdc2dc5 SHA256: b6472da2cc868ec09c472acec226d95ac04e0a322db4b9b3ea61c38e5768435b —————————————————————————————————————————- Installation […]
More…

Removed: abiautsh.dll

Malware: C:\sand-box\software.exe Removed: C:\WINDOWS\system32\abiautsh.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.24 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.03.24 Trojan.Win32.Inject.aoae McAfee 5929 2010.03.23 – Microsoft 1.5605 2010.03.24 Trojan:Win32/Pucodex.A NOD32 4969 2010.03.23 Win32/Spy.Agent.NRE —————————————————————————————————————————- Additional information File size: 78336 bytes MD5   : 075b56077921864e43a6f1c753580474 SHA1  : a6e01c960b12aa641940b7d00a2a6e37f7094c4d SHA256: 8b8588594f0455ed9647b751c958a3c5ecc924e69e7b1fad0c4d38ab0b3b752f —————————————————————————————————————————- Installation When the program is executed, it creates the following registry […]
More…

Removed: REGSRV.EXE, STDRT.EXE

Malware: 48545af0b55a8704de5a2916d40e1763.exe Removed: C:\WINDOWS\SYSTEM\REGSRV.EXE C:\WINDOWS\TEMP\MRT2.TMP\STDRT.EXE —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.17 – Kaspersky 7.0.0.125 2010.03.17 Hoax.Win32.BadJoke.Formatter.j McAfee 5922 2010.03.16 – Microsoft 1.5605 2010.03.17 – NOD32 4950 2010.03.16 – —————————————————————————————————————————- Additional information File size: 675033 bytes MD5 : 6c4661d4d840f5903381c5dc66382aef SHA1 : 94fd4657cedf276724c8c66cd4ec6571bfa5ab2c SHA256: 9cbd2f51a1102b69a78f2522325048c23de53acb33bc333d236567c0fa0505fb —————————————————————————————————————————- Installation When the program is executed, it […]
More…

Removed: ave.exe (FakeAV – XP AntiMalware 2010, aka Antivirus XP 2010)

Malware: C:\sand-box\3af31e07dde54af9a849a1f6256328ca.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.23 – Kaspersky 7.0.0.125 2010.03.22 – McAfee 5928 2010.03.22 – Microsoft 1.5605 2010.03.22 Trojan:Win32/FakeRean NOD32 4966 2010.03.22 a variant of Win32/Kryptik.DFO —————————————————————————————————————————- Additional information File size: 204800 bytes MD5 : 0e127b49bf372a4189b59f7aae0555f6 SHA1 : b1a8342910c546bd117e7bafd508e68fdc380207 SHA256: 1db7faf308fde71a50a937e2aa82960d3d318fd154670874584f2a651633097c —————————————————————————————————————————- Installation […]
More…

Removed: plugin.exe (Locker)

Malware: n002102807r0019Rd111be33X0ee8f3ecY45492f8bZ070f0120316P000500071[1].exe Removed: C:\Program Files\plugin.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.19 – Kaspersky 7.0.0.125 2010.03.19 Trojan-Ransom.Win32.PornoBlocker.rh McAfee 5924 2010.03.18 – Microsoft 1.5605 2010.03.19 – NOD32 4957 2010.03.19 – —————————————————————————————————————————- Additional information File size: 374784 bytes MD5 : d67b3c6c3db208a9db85b0cf5c3859c5 SHA1 : aabe35b8bb15c13e87b26736f61dda40cc8b81b9 SHA256: 37904ada715cc879d45cd3cdf6ac042a7f006ced615d783d9ea72c449029ef92 —————————————————————————————————————————- Installation When the program is executed, it […]
More…

Removed: TWAIN32.EXE

Malware: Sexosbbb10.com.exe Removed: C:\WINDOWS\TWAIN32.EXE —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.22 Gen:Trojan.Heur.PT.bm0@beU@@9ni Kaspersky 7.0.0.125 2010.03.22 Trojan-Downloader.Win32.Agent.djis McAfee 5928 2010.03.22 – Microsoft 1.5605 2010.03.22 TrojanDownloader:Win32/Small.gen!AO NOD32 4966 2010.03.22 a variant of Win32/TrojanDownloader.VB.NUI —————————————————————————————————————————- Additional information File size: 24576 bytes MD5 : 09c92f87fad60342a8f55a0629078ad9 SHA1 : 11ff052eda2b5b02231ab9d330bdae4dfb409cf8 SHA256: 3937e9df0e0d6b015b36832934e6431dc0025eb3e4b276c6f8c08133bfb31860 —————————————————————————————————————————- Installation When the program is […]
More…

Removed: 0040.DLL

Malware: Browser_Update.exe Removed: C:\WINDOWS\system32\0040.DLL —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.23 – Kaspersky 7.0.0.125 2010.03.23 Trojan-Spy.Win32.Insain.mi McAfee 5929 2010.03.23 – Microsoft 1.5605 2010.03.23 TrojanDropper:Win32/Witkinat.A NOD32 4969 2010.03.23 Win32/Witkinat.A —————————————————————————————————————————- Additional information File size: 40832 bytes MD5 : 99305d34ad7a4e62bf1bfe397c2b3e32 SHA1 : e65f1dcb09e1450c6e754e5ddf7a6254a91666f8 SHA256: dd28c72f85095d7529be974de3c8ef175eb2bb60599fff49c111115d37925ec1 —————————————————————————————————————————- Installation When the program is executed, it creates […]
More…