Removed: C:\Documents and Settings\Administrator\ctfmon.exe (worm Rimecud)

May 23, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Removed: C:\Documents and Settings\Administrator\ctfmon.exe —————————————————————————————————————————- Detected by UnHackMe in “Malti AV scan”: CTFMON.EXE Default location: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\CTFMON.EXE MD5: 26CD08E868F9FDE5F28A6634B3E42F13 SHA1: 2CAFF9A7 B11C67DC 1943A74B ADB6C90E A7637E78 File Size: 159 744 Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.05.22 Gen:Variant.Rimecud.2 Kaspersky 7.0.0.125 2010.05.23 – Microsoft 1.5802 2010.05.23 [...]

Removed: servicelayer.exe, svw.exe, C:\WINDOWS\lsass.exe, svc.exe, svchosty.exe, C:\WINDOWS\ctfmon.exe (trojan Microjoin)

May 4, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: Removed: C:\WINDOWS\servicelayer.exe C:\WINDOWS\svw.exe C:\WINDOWS\lsass.exe C:\WINDOWS\svc.exe C:\Documents and Settings\Administrator\Local Settings\Temp\ope6.exe C:\Documents and Settings\Administrator\Local Settings\Temp\svchosty.exe C:\WINDOWS\ctfmon.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: servicelayer Author: Unknown Related File: C:\WINDOWS\SERVICELAYER.EXE Type: Registry Run Item Name: netw Author: Unknown Related File: C:\WINDOWS\SVW.EXE Type: Registry Run Item Name: lsass Author: Unknown Related File: C:\WINDOWS\LSASS.EXE Type: Registry Run Item Name: netc [...]

Removed: ..\system32\keepsafe.exe / Restored: ..\system32\ctfmon.exe

April 10, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: laoshuxzz1.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\keepsafe.exe —————————————————————————————————————————- Restored: C:\WINDOWS\system32\ctfmon.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.05 – Kaspersky 7.0.0.125 2010.04.05 Trojan.Win32.Antavmu.hgs Microsoft 1.5605 2010.04.05 TrojanDownloader:Win32/Small.gen!D NOD32 4999 2010.04.04 – —————————————————————————————————————————- Additional information File size: 49152 bytes MD5   : e0a226485796d0976200bdcd2d3456ad SHA1  : cc40e22de18f537fb0c0d1798c12db322d69e87b SHA256: c5d7d812d8503743a0af2485d715fea5182926ba58e2a1961dc1b75201faa8b1 —————————————————————————————————————————- Detected by UnHackMe: Item Name: TXMouie Author: Unknown Related File: C:\WINDOWS\SYSTEM32\KEEPSAFE.EXE [...]

Removed: ctfmon.exe, lsass.exe, odbnsy.exe, sms.exe, svc.exe, svw.exe

March 18, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: 50.exe Removed: C:\WINDOWS\ctfmon.exe C:\WINDOWS\lsass.exe C:\WINDOWS\odbnsy.exe C:\WINDOWS\sms.exe C:\WINDOWS\svc.exe C:\WINDOWS\svw.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.17 Trojan-Dropper:W32/Mudrop.D Kaspersky 7.0.0.125 2010.03.17 Trojan-Dropper.Win32.Mudrop.hch McAfee 5922 2010.03.16 – Microsoft 1.5605 2010.03.17 TrojanDropper:Win32/Microjoin.gen!B NOD32 4950 2010.03.16 a variant of Win32/Kryptik.CZA —————————————————————————————————————————- Additional information File size: 2384384 bytes MD5   : a8edb5fae8980dcfd4bfa83c415dd761 SHA1  : df248d95560bb7c03c70fcfa053f9f2f52a4e306 SHA256: b6b1a7af5229f62e4cbd538102cadb79416334ca87d3b1a7962a9a50c269c48e —————————————————————————————————————————- Installation When the [...]

Removed: servicelayer.exe, wdmon.exe, svw.exe, ctfmon.exe, amoumain.exe

January 28, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: 123.exe Removed: C:\WINDOWS\servicelayer.exe C:\WINDOWS\wdmon.exe C:\WINDOWS\svw.exe C:\WINDOWS\ctfmon.exe C:\WINDOWS\amoumain.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.26 – Kaspersky 7.0.0.125 2010.01.26 Trojan-Dropper.Win32.Mudrop.fuc McAfee 5872 2010.01.25 – Microsoft 1.5405 2010.01.26 – NOD32 4806 2010.01.26 – Symantec 20091.2.0.41 2010.01.26 – —————————————————————————————————————————- Additional information File size: 2661888 bytes MD5 : 6411876d41f55fa21003afe9256b24d2 SHA1 : 8c7c365fa01cd64f7d20536c5d11d4c932c80ac9 SHA256: e8cbf67fff6888ff759fa59af3dbeabd2416db777c5b6593b9b09bf232d20536 —————————————————————————————————————————- [...]