Removed: winlogon32.exe, SMSS32.EXE (FakeAlert)

April 19, 2010 by NightWatcher · Leave a Comment
Filed under: FakeAV, Malware 

Malware: exe.exe Removed: C:\WINDOWS\system32\winlogon32.exe C:\WINDOWS\SYSTEM32\SMSS32.EXE —————————————————————————————————————————- Detected by UnHackMe: Item Name: UserInit Author: Unknown Related File: C:\WINDOWS\system32\winlogon32.exe Type: UserInit Value Item Name: smss32.exe Author: QnXi Related File: C:\WINDOWS\SYSTEM32\SMSS32.EXE Type: Registry Run Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.18 Trojan.Generic.3116009 Kaspersky 7.0.0.125 2010.04.18 Trojan-Downloader.Win32.FraudLoad.wxtw McAfee 5.400.0.1158 [...]

Removed: helper32.dll, winlogon32.exe, smss32.exe

February 17, 2010 by NightWatcher · Leave a Comment
Filed under: FakeAV, Malware 

—————————————————————————————————————————- Malware: exe.exe Removed: C:\WINDOWS\system32\helper32.dll C:\WINDOWS\system32\winlogon32.exe C:\WINDOWS\system32\smss32.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.13 – Kaspersky 7.0.0.125 2010.02.13 Trojan.Win32.FraudPack.alhw McAfee 5891 2010.02.13 – Microsoft 1.5406 2010.02.13 – NOD32 4864 2010.02.13 – Symantec 20091.2.0.41 2010.02.13 Suspicious.Insight —————————————————————————————————————————- Additional information File size: 40960 bytes MD5 : 831489d4a74ee66ba92aede4f983b1e9 SHA1 : c542590896eb710ca38ecffb3cce5ad7ca96dd25 SHA256: bc47593696b4f63738ea45a48be15be950deebf00e536ea628215d4c14ba9e2e —————————————————————————————————————————- Installation [...]

Removed: helper32.dll, winlogon32.exe, smss32.exe, IS2010.exe

February 10, 2010 by NightWatcher · Leave a Comment
Filed under: FakeAV, Malware 

Malware: yahoo.exe Removed: C:\WINDOWS\system32\helper32.dll C:\WINDOWS\system32\winlogon32.exe C:\WINDOWS\system32\smss32.exe C:\Program Files\InternetSecurity2010\IS2010.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.10 – Kaspersky 7.0.0.125 2010.02.10 Trojan.Win32.Agent2.lid McAfee 5888 2010.02.10 Downloader-CFA Microsoft 1.5406 2010.02.10 TrojanDownloader:Win32/Fakeinit NOD32 4854 2010.02.10 Win32/TrojanDownloader.FakeAlert.AED Symantec 20091.2.0.41 2010.02.10 Trojan.FakeAV!gen18 —————————————————————————————————————————- Additional information File size: 36864 bytes MD5 : 6fd8a1122cdde897ab88cec08cb2c468 SHA1 : 5cc2bb702519c4df44311ea0b47d51249881cffa SHA256: 4ce879fc865fd2ccc365f54311b9211e854c5d9d7d7ff6e75bd20a6f0907413a —————————————————————————————————————————- [...]

Removed: winlogon32.exe, IS2010.exe, smss32.exe, helper32.dll

February 2, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: b4f489c005cfa1b0a3e2c93b305a5399.exe Removed: C:\WINDOWS\system32\winlogon32.exe C:\Program Files\InternetSecurity2010\IS2010.exe C:\WINDOWS\system32\smss32.exe C:\WINDOWS\system32\helper32.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.01 – Kaspersky 7.0.0.125 2010.02.01 – McAfee 5878 2010.01.31 Generic FakeAlert.c Microsoft 1.5406 2010.02.01 – NOD32 4823 2010.02.01 – Symantec 20091.2.0.41 2010.02.01 Trojan.FakeAV!gen17 —————————————————————————————————————————- Additional information File size: 33280 bytes MD5 : c0ed88ccdc920a951f750c53b21996a1 SHA1 : fd0ccd3052bbaea4e1dc5f2b0e542e2a413dd939 SHA256: e5c6de61d8457d46248ea9623fe5a5521ba10102f1dc74689c698c458466fe8f [...]

Removed: winlogon32.exe, smss32.exe, helper32.dll

January 17, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: 4349a84aa5ed87d5773593f8f993f067.exe Removed: C:\WINDOWS\system32\winlogon32.exe C:\WINDOWS\system32\smss32.exe C:\WINDOWS\system32\helper32.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.17 – Kaspersky 7.0.0.125 2010.01.17 Trojan-Downloader.Win32.FraudLoad.gjs McAfee 5863 2010.01.16 – Microsoft 1.5302 2010.01.16 TrojanDownloader:Win32/Fakeinit NOD32 4778 2010.01.16 Win32/TrojanDownloader.FakeAlert.AED Symantec 20091.2.0.41 2010.01.17 – —————————————————————————————————————————- Additional information File size: 31744 bytes MD5 : 2402f97bbd41e9f761533804fc795aa7 SHA1 : b7714657be0e763cbe5fb60f05c26cc2d6138ce7 SHA256: 4563d174a8cbb91e8f26e2da08b692ead904df075888da32f698d5db68353dfd —————————————————————————————————————————- Installation When [...]