WindowsWebSecurity.exe – Porn Locker

April 17, 2011 by NightWatcher
Filed under: Ransomware 
: Solved!

Fix it immediately:

We checked some samples of WindowsWebSecurity.exe and detected the file WindowsWebSecurity.exe as threat.
Remove the WindowsWebSecurity.exe from your computer right now.
Removal tool: http://www.unhackme.com

Malware Analysis of WindowsWebSecurity.exe
Executed: c:\sand-box\WindowsWebSecurity.exe
Removed: WindowsWebSecurity.exe. Full path: c:\sand-box\WindowsWebSecurity.exe

—————————————————————————————————————————-
Detected by RegRun Warrior:

1. RegRun Reanimator:

Item Name: ktdjffu
Author: Company
Related File: C:\SAND-BOX\WindowsWebSecurity.exe
Type: Scheduled Tasks

2. Multi AntiVirus scan:

- none -

Removal Results: Success
Number of reboot: 1

—————————————————————————————————————————-
How to quickly detect malware presence?

Files:
C:\WINDOWS\Tasks\pfpefsvmgsg.job
—————————————————————————————————————————-
Classification:

Antivirus Version Last Update Result
F-Secure 9.0.16440.0 2011.03.22 -
Microsoft 1.6603 2011.03.22 Trojan:Win32/Serubsit.A
NOD32 5974 2011.03.22 Win32/LockScreen.AFD

—————————————————————————————————————————-

MD5 718c54f733cad5efa8752580106b9a75

SHA1 d3970b43f6c9754e6ddd6153d8ba847ab3585fde

SHA256 95897f9c0c263ed142e720233b15d07f4e4e6b3bcea5e31fcc6fbd5ab323f5b9

—————————————————————————————————————————-


Installation
When the program is executed, it creates the following registry subkeys and values:

———————————-
Files added:2
———————————-
C:\Documents and Settings\All Users\Application Data\~f926.tmp
C:\WINDOWS\Tasks\pfpefsvmgsg.job

———————————-
Files [attributes?] modified:0
———————————-

———————————-
Total changes:2
———————————-

—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com


Recommended: UnHackMe anti-rootkit and anti-malware

Premium software: RegRun Security Suite (Good choice for removal and protection)

Written by

Malware Hunter.

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!

You must be logged in to post a comment.