Internet-Explorer_update.exe – Porn Locker
We checked some samples of Internet-Explorer_update.exe and detected the file Internet-Explorer_update.exe as threat.
Remove the Internet-Explorer_update.exe from your computer right now.
Removal tool: http://www.unhackme.com
Malware Analysis of Internet-Explorer_update.exe
Executed: c:\sand-box\Internet-Explorer_update.exe
Removed: Internet-Explorer_update.exe. Full path: c:\sand-box\Internet-Explorer_update.exe
—————————————————————————————————————————-
Detected by RegRun Warrior:
1. RegRun Reanimator:
Item Name: ktdjffu
Author: Company
Related File: C:\SAND-BOX\Internet-Explorer_update.exe
Type: Scheduled Tasks
2. Multi AntiVirus scan:
- none -
Removal Results: Success
Number of reboot: 1
—————————————————————————————————————————-
How to quickly detect malware presence?
Files:
C:\WINDOWS\Tasks\cknoxqwowwrs.job
—————————————————————————————————————————-
Classification:
| Antivirus | Version | Last Update | Result |
|---|---|---|---|
| F-Secure | 9.0.16440.0 | 2011.03.22 | Trojan.Generic.KD.156464 |
| Kaspersky | 7.0.0.125 | 2011.03.22 | Trojan.Win32.FakeWarn.d |
| Microsoft | 1.6603 | 2011.03.22 | Trojan:Win32/Serubsit.A |
| NOD32 | 5973 | 2011.03.22 | Win32/LockScreen.AFD |
—————————————————————————————————————————-
MD5 6a92528b10e0392897110022fa3dddfa
SHA1 6de6d66727b64286379b4b2ba4a3abee2cf912ca
SHA256 b645cbce823ab13478c6a3d6b1222d82d37426aa20222c7cde92c0d439fbc19f
—————————————————————————————————————————-
Installation
When the program is executed, it creates the following registry subkeys and values:
———————————-
Files added:2
———————————-
C:\Documents and Settings\All Users\Application Data\~f926.tmp
C:\WINDOWS\Tasks\cknoxqwowwrs.job
———————————-
Total changes:2
———————————-
—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com
Recommended: UnHackMe anti-rootkit and anti-malware
Premium software: RegRun Security Suite (Good choice for removal and protection)




