Removed: ave.exe (FakeAV XP AntiMalware aka Antivirus XP 2010)

April 27, 2010 by NightWatcher · Leave a Comment
Filed under: FakeAV, Malware 

Malware: C:\sand-box\fid.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: .exe Author: Unknown Related File: “C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe” /START “%1″ %* Type: Main File Extensions Item Name: ave.exe Author: Unknown Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\AVE.EXE Type: Running Processes Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: [...]

Removed: ..\Application Data\ave.exe (Fake Antivirus XP 2010 – malware changes its name every time Windows starts)

April 7, 2010 by NightWatcher · Leave a Comment
Filed under: FakeAV, Malware 

Malware: C:\sand-box\9d7f6d5b600546373cafc42bc5a2a670.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.02 Trojan-Spy:W32/Zbot.gen!G Kaspersky 7.0.0.125 2010.04.02 Packed.Win32.Katusha.j McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.04.02 Trojan:Win32/FakeRean NOD32 4995 2010.04.02 a variant of Win32/Kryptik.DFO —————————————————————————————————————————- Additional information File size: 195584 bytes MD5   : b4492af4de0daae0dc91c5c81c3956b6 SHA1  : 968d29a9efe3401dc458d32d9df5fdd0ff9a4a03 SHA256: 70a91b85687d288548a3fab819040f05626c56248fde37fe1d315a1bf5208d3d —————————————————————————————————————————- Installation When the program [...]

Removed: ave.exe (Fake AV – Antispyware XP – old name Antivirus XP 2010)

March 22, 2010 by NightWatcher · Leave a Comment
Filed under: FakeAV, Malware 

Malware: C:\sand-box\6cec5ab7a3a9127f14c5abe1e1c2790d.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.19 Gen:Heur.Krypt.26 Kaspersky 7.0.0.125 2010.03.19 – McAfee 5925 2010.03.19 – Microsoft 1.5605 2010.03.19 – NOD32 4959 2010.03.19 a variant of Win32/Kryptik.DBC —————————————————————————————————————————- Additional information File size: 203776 bytes MD5   : 94fd818ffbccb44a8bfab1d0759e1b79 SHA1  : a075f8bb1802ee7af775f8e518e6124cb658fa1a SHA256: 38f89a9f27cfbc9288550198702ef17687e1cd305484445b9bcc13e823c6b8b2 —————————————————————————————————————————- Installation When the program [...]

Removed: ave.exe (Fake AV – XP Smart Security 2010, old name Antivirus XP 2010)

March 21, 2010 by NightWatcher · Leave a Comment
Filed under: FakeAV, Malware 

Malware: C:\sand-box\fid.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.20 Gen:Heur.Krypt.26 Kaspersky 7.0.0.125 2010.03.20 Trojan.Win32.FraudPack.aowt McAfee 5925 2010.03.19 – Microsoft 1.5605 2010.03.19 – NOD32 4959 2010.03.19 a variant of Win32/Kryptik.DBC —————————————————————————————————————————- Additional information File size: 201216 bytes MD5 : dc42bb84ffcd6036b8eefdf26fad9ef8 SHA1 : b1383b739b72da64ae31a4c9064778ca075594c1 SHA256: 514992e4ca7c42bd41be4f841b0b1827b3e8397c0f6aee2336f93aefdd8aba81 —————————————————————————————————————————- Installation [...]

Removed: ave.exe (Fake AV – Total XP Security – old name – Antivirus XP 2010)

March 19, 2010 by NightWatcher · Leave a Comment
Filed under: FakeAV, Malware 

Malware: C:\sand-box\feed.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.18 – Kaspersky 7.0.0.125 2010.03.18 – McAfee 5923 2010.03.17 – Microsoft 1.5605 2010.03.17 – NOD32 4954 2010.03.18 Win32/Adware.XPAntiSpyware.AA —————————————————————————————————————————- Additional information File size: 201728 bytes MD5   : 669cb94519d39ba684747f1637ae76a9 SHA1  : fa049d51d9d9b79f04b76deb0721673c579fd5c0 SHA256: be763d2225345f058de282983f0e8bdd6a6753e62cb6733a7c84161112f1d98e —————————————————————————————————————————- Installation When the program is executed, it [...]

Removed: ave.exe (Fake AV – Antivirus XP 2010)

March 18, 2010 by NightWatcher · Leave a Comment
Filed under: FakeAV, Malware 

Malware: C:\sand-box\9e34670d9cac24e39deb21bd6de08cf9.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.16 Trojan.Generic.KD.4145 Kaspersky 7.0.0.125 2010.03.16 – McAfee 5922 2010.03.16 – Microsoft 1.5605 2010.03.16 Trojan:Win32/FakeRean NOD32 4950 2010.03.16 a variant of Win32/Kryptik.DBC —————————————————————————————————————————- Additional information File size: 200704 bytes MD5   : 53cebd78d4f2b15da7118f8e64d4b9ff SHA1  : 3d993bca6f17a018f936bbe382c6aacd1c6c1242 SHA256: 23353babf24cfc7ba0c2f56b4b32135cd7f414f384c917721d8b8387a589fa8a —————————————————————————————————————————- Installation When the program [...]