Removed: cleansweep.exe, ziavgrixxx.exe (trojan SpyEyes)

September 13, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: C:\sand-box\load.exe Removed: C:\cleansweep.exe\cleansweep.exe C:\ziavgrixxx.exe\ziavgrixxx.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: cleansweep.exe Author: Related File: C:\CLEANSWEEP.EXE\CLEANSWEEP.EXE Type: Registry Run Item Name: ziavgrixxx.exe Author: Related File: C:\ZIAVGRIXXX.EXE\ZIAVGRIXXX.EXE Type: Registry Run Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- How to quickly detect malware presence? Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\cleansweep.exe Value: “C:\cleansweep.exe\cleansweep.exe” Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ziavgrixxx.exe Value: “C:\ziavgrixxx.exe\ziavgrixxx.exe” Folders: C:\cleansweep.exe\ C:\ziavgrixxx.exe\ Files: [...]

Removed: C:\windrvxxxx.exe\windrvxxxx.exe (trojan Pincav – new version cleansweep.exe)

July 9, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: build3.exe Removed: C:\windrvxxxx.exe\windrvxxxx.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: windrvxxxx.exe Author: Unknown Related File: C:\WINDRVXXXX.EXE\WINDRVXXXX.EXE Type: Registry Run Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- How to quickly detect malware presence? Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\windrvxxxx.exe Value: “C:\windrvxxxx.exe\windrvxxxx.exe” Folders: C:\windrvxxxx.exe\ Files: C:\windrvxxxx.exe\config.bin C:\windrvxxxx.exe\windrvxxxx.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.07.08 Trojan.Generic.KD.19008 Kaspersky 7.0.0.125 [...]

Removed: C:\cleansweep.exe\cleansweep.exe, C:\outbackxxx.exe\outbackxxx.exe (trojan SpyEyes)

July 7, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: build.exe Removed: C:\cleansweep.exe\cleansweep.exe C:\outbackxxx.exe\outbackxxx.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: cleansweep.exe Author: Unknown Related File: C:\CLEANSWEEP.EXE\CLEANSWEEP.EXE Type: Registry Run Item Name: outbackxxx.exe Author: Unknown Related File: C:\OUTBACKXXX.EXE\OUTBACKXXX.EXE Type: Registry Run Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- How to quickly detect malware presence? Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\cleansweep.exe Value: “C:\cleansweep.exe\cleansweep.exe” Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\outbackxxx.exe Value: “C:\outbackxxx.exe\outbackxxx.exe” Folders: C:\cleansweep.exe [...]

Removed: C:\WINDOWS:LIVEUPDATE.EXE C:\outbackxxx.exe\outbackxxx.exe (trojan PinkBlocker – new version cleansweep.exe)

July 7, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: outback.exe Removed: C:\WINDOWS:LIVEUPDATE.EXE C:\outbackxxx.exe\outbackxxx.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: {AF1DD320-6D79-6AF3-561C-8786A22DE311} Author: Unknown Related File: C:\WINDOWS:LIVEUPDATE.EXE Type: ActiveSetup Item Name: outbackxxx.exe Author: Unknown Related File: C:\OUTBACKXXX.EXE\OUTBACKXXX.EXE Type: Registry Run Item Name: LiveUpdate.exe Author: Unknown Related File: C:\WINDOWS:LIVEUPDATE.EXE Type: Registry Run Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- How to quickly detect malware presence? [...]

Removed: C:\cleansweep.exe\cleansweep.exe (trojan SpyEyes)

May 25, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: load.exe Removed: C:\cleansweep.exe\cleansweep.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: cleansweep.exe Author: Related File: C:\CLEANSWEEP.EXE\CLEANSWEEP.EXE Type: Registry Run Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.05.25 Trojan.Generic.KD.13526 Kaspersky 7.0.0.125 2010.05.25 Trojan-Spy.Win32.SpyEyes.if Microsoft 1.5802 2010.05.24 – NOD32 5142 2010.05.24 – —————————————————————————————————————————- Additional information File size: 150016 bytes [...]

Removed: cleansweep.exe

March 16, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: build.exe Removed: C:\cleansweep.exe\cleansweep.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.16 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.03.16 Trojan-Spy.Win32.SpyEyes.ca McAfee 5921 2010.03.15 – Microsoft 1.5605 2010.03.16 Trojan:Win32/Spyeye NOD32 4949 2010.03.16 a variant of Win32/Kryptik.DAW —————————————————————————————————————————- Additional information File size: 84992 bytes MD5 : 95bf0d6d779a991d67c07cab19ca3ea2 SHA1 : a86aa3359dfcde9f1a43393020bf55499965dd9c SHA256: 0dfeffdc6028ba5010ac961e91739c527812b48ada74c2b374f8873ca3fdcd39 —————————————————————————————————————————- Installation When the program is [...]

Removed: cleansweep.exe, nynw.wmo

March 3, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: svchoct.exe Removed: C:\cleansweep.exe\cleansweep.exe C:\WINDOWS\system32\nynw.wmo —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.03 Trojan-Spy:W32/Spyeye.C Kaspersky 7.0.0.125 2010.03.03 Trojan-Spy.Win32.SpyEyes.as McAfee 5909 2010.03.03 Generic PWS.y!cbh Microsoft 1.5502 2010.03.03 – NOD32 4912 2010.03.03 Win32/Spy.SpyEye.AS —————————————————————————————————————————- Additional information File size: 155648 bytes MD5 : 91aa0ce3c1581b6a581b4cdc665c13fb SHA1 : 30fa007c10a5a83102eaefacfa6b1db2db6b3f62 SHA256: 9e79ce21868887391b0be162b1d09667e041621a9819f943b5ef1ace17ccf332 —————————————————————————————————————————- Installation When the program is executed, [...]

Removed: cleansweep.exe

February 17, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: bt_get.exe Removed: C:\cleansweep.exe\cleansweep.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.13 – Kaspersky 7.0.0.125 2010.02.13 Trojan-Spy.Win32.SpyEyes.e McAfee 5890 2010.02.12 Generic PWS.y!byc Microsoft 1.5406 2010.02.13 Trojan:Win32/Spyeye NOD32 4862 2010.02.12 a variant of Win32/Spy.SpyEye.B Symantec 20091.2.0.41 2010.02.13 Trojan.Spyeye —————————————————————————————————————————- Additional information File size: 131072 bytes MD5 : 3da127c898d0df2c15165e4af8f61d5c SHA1 : c9d77cb4b92a606122e8c19a801c0a0af66f0696 SHA256: 29e261b1bc20231df371c5718d9619c2445cb31260609e6a4787395b1382d883 —————————————————————————————————————————- [...]

Removed: cleansweep.exe

February 12, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: build.exe Removed: C:\cleansweep.exe\cleansweep.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.12 Trojan-Spy:W32/Spyeye.A Kaspersky 7.0.0.125 2010.02.12 Trojan-Spy.Win32.SpyEyes.d McAfee 5890 2010.02.12 Spyeye Microsoft 1.5406 2010.02.12 Trojan:Win32/Spyeye NOD32 4861 2010.02.12 Win32/Spy.SpyEye.B Symantec 20091.2.0.41 2010.02.12 Trojan.Spyeye —————————————————————————————————————————- Additional information File size: 126464 bytes MD5 : 84714c100d2dfc88629531f6456b8276 SHA1 : ecce2684f143b02fc187a4a6af22f1e9ed6c2c6f SHA256: 861aa9c5ddcb5284e1ba4e5d7ebacfa297567c353446506ee4b4e39c84454b09 —————————————————————————————————————————- Installation When the program [...]

Removed: cleansweep.exe

February 7, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: taskmgr.exe Removed: C:\cleansweep.exe\cleansweep.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.02 Suspicious:W32/Malware!Online Kaspersky 7.0.0.125 2010.02.02 Trojan.Win32.Pincav.qrg McAfee 5879 2010.02.01 Generic.dx!mez Microsoft 1.5406 2010.02.02 – NOD32 4827 2010.02.02 a variant of Win32/Agent.QQS —————————————————————————————————————————- Additional information File size: 56832 bytes MD5 : 97c73a29ab07f04458f5e8834f8db1ba SHA1 : 171565913cf53864c0ba1ff9dc414ed6ac473662 SHA256: a7b061a30f875be1de8994084f2935175ccb4edce87a88fc4430c63e0f738376 —————————————————————————————————————————- Installation When the program is [...]

Removed: cleansweep.exe

January 15, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: load_the.exe Removed: C:\cleansweep.exe\cleansweep.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.15 Trojan-Downloader:W32/Agent.MXY Kaspersky 7.0.0.125 2010.01.15 Trojan.Win32.Pincav.pgq McAfee 5861 2010.01.14 Suspect-02!A977C34CDD80 Microsoft 1.5302 2010.01.14 – NOD32 4773 2010.01.15 – Symantec 20091.2.0.41 2010.01.15 Suspicious.MH690.A —————————————————————————————————————————- Additional information File size: 70144 bytes MD5 : a977c34cdd8036595ee23e5ac8259e12 SHA1 : 0e166a8a1126fddaa846e86392a1294d27d67731 SHA256: 3700bb6bfbabcb9534788b81116a0fdc605d9e18b76f3a100225596eae56eda3 —————————————————————————————————————————- Installation When the program [...]