Removed: C:\WINDOWS\svchost.exe (trojan VBInject)
Malware: load.exe Removed: C:\WINDOWS\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: svchost.exe Author: Related File: C:\WINDOWS\SVCHOST.EXE Type: Detected using Heuristic Algorithm Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- How to quickly detect malware presence? Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Services Value: “svchost.exe” Registry: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\Windows Services Value: “svchost.exe” Files: C:\WINDOWS\svchost.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result [...]
Removed: C:\Documents and Settings\Administrator\Application Data\Microsoft\svchost.exe (trojan Swisyn)
Malware: exe.exe Removed: C:\Documents and Settings\Administrator\Application Data\Microsoft\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: svchost Author: Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MICROSOFT\SVCHOST.EXE Type: Registry Run Item Name: svchost.exe Author: Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MICROSOFT\SVCHOST.EXE Type: Running Processes Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- How to quickly detect malware presence? Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\svchost Value: “C:\Documents [...]
Removed: C:\WINDOWS\Temp\spoolsv\spoolsv.exe, C:\WINDOWS\svchost.exe (trojan Zapchast)
Malware: postcard.scr.exe Removed: C:\WINDOWS\Temp\spoolsv\spoolsv.exe C:\WINDOWS\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: spoolsv Author: mIRC Co. Ltd. Related File: C:\WINDOWS\TEMP\SPOOLSV\SPOOLSV.EXE Type: Registry Run Item Name: svchost Author: Unknown Related File: C:\WINDOWS\SVCHOST.EXE Type: Registry Run Item Name: spoolsv.exe Author: mIRC Co. Ltd. Related File: C:\WINDOWS\TEMP\SPOOLSV\SPOOLSV.EXE Type: Running Processes Item Name: svchost.exe Author: Unknown Related File: C:\WINDOWS\SVCHOST.EXE Type: [...]
Removed: ..\Local Settings\Temp\svchost.exe (trojan Lolmehot)
Malware: Serverr.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: UserInit Author: Unknown Related File: C:\WINDOWS\SYSTEM32\Userinit.exe,C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe Type: UserInit Value Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- How to quickly detect malware presence? Registry: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit Value: “C:\WINDOWS\SYSTEM32\Userinit.exe,C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe” Files: C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe C:\WINDOWS\system32\drivers\tmpp.exe C:\WINDOWS\system32.htm C:\WINDOWS\tmpp.log [...]
Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe (trojan Jorik.IRCbot)
Malware: upxbunnn.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: Windows Firewall Author: WI7u9BjP9Qjs0r Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SVCHOST.EXE Type: Registry Run Item Name: svchost.exe Author: Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SVCHOST.EXE Type: Running Processes Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- How to quickly detect malware presence? Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Firewall Value: “C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\svchost.exe” Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Firewall [...]
Removed: C:\Program Files\Micorosoft Visual\svchost.exe (trojan Malex)
Malware: C:\sand-box\desktop.exe Removed: C:\Program Files\Micorosoft Visual\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: Server Process Loader Author: BitDefender Related File: “C:\Program Files\Micorosoft Visual\svchost.exe” Type: Auto Services Item Name: svchost.exe Author: BitDefender Related File: C:\PROGRAM FILES\MICOROSOFT VISUAL\SVCHOST.EXE Type: Running Processes Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- How to quickly detect malware presence? Registry: HKLM\System\CurrentControlSet\Services\Server Process [...]
Removed: C:\Documents and Settings\Administrator\Application Data\dll\svchost.exe (worm Tawsebot)
Malware: load.exe Removed: C:\Documents and Settings\Administrator\Application Data\dll\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: UserInit Author: Unknown Related File: C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\Administrator\Application Data\dll\svchost.exe, Type: UserInit Value Item Name: dll Author: Microsoft Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\DLL\SVCHOST.EXE Type: Registry Run Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- How to quickly detect malware presence? Registry: HKLM\Software\Microsoft\Windows [...]
Removed: adc_w32.dll, alggui.exe, svchost.exe (FakeAV – Sysinternals Antivirus aka Your PC Protector)
Malware: C:\sand-box\Windows_Protector.exe Removed: C:\Program Files\adc_w32.dll C:\Program Files\alggui.exe C:\Program Files\svchost.exe —————————————————————————————————————————- Detected by RegRun Warrior: 1. RegRun Reanimator: 1.1 Item Name: {149256D5-E103-4523-BB43-2CFB066839D6} Author: Sysint ltd. Related File: C:\PROGRAM FILES\ADC_W32.DLL Type: Browser Helper Objects 1.2 Item Name: .exe Author: Unknown Related File: C:\Program Files\alggui.exe “%1″ %* Type: Main File Extensions 1.3 Item Name: AdbUpd Author: Related File: [...]
Removed: alggui.exe, adc_w32.dll C:\Program Files\svchost.exe (FakeAV – XJR Antivirus aka AKM Antivirus 2010 Pro)
Malware: C:\sand-box\Windows_Protector.exe Removed: C:\Program Files\alggui.exe C:\Program Files\adc_w32.dll C:\Program Files\svchost.exe —————————————————————————————————————————- Detected by RegRun Warrior: Item Name: .exe Author: Unknown Related File: C:\Program Files\alggui.exe “%1″ %* Type: Main File Extensions Item Name: {149256D5-E103-4523-BB43-2CFB066839D6} Author: ADC – AntiSpyware Related File: C:\PROGRAM FILES\ADC_W32.DLL Type: Browser Helper Objects Item Name: AdbUpd Author: Related File: C:\PROGRAM FILES\SVCHOST.EXE Type: Drivers Removal [...]
Removed: C:\WINDOWS\svchost.exe (trojan VBInject)
Malware: IOIzo4rkW5V3SseNqcRE1OZu.exe Removed: C:\WINDOWS\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: svchost.exe Author: Rundll32 Related File: C:\WINDOWS\SVCHOST.EXE Type: Detected using Heuristic Algorithm Item Name: Microsoft© Operating System: Author: Related File: C:\WINDOWS\SVCHOST.EXE Type: Registry Run Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.05.22 – Kaspersky 7.0.0.125 2010.05.22 – [...]
Removed: C:\WINDOWS\system\svchost.exe (trojan-spy Agent)
Malware: killaa.exe Removed: C:\WINDOWS\system\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: svchost Author: Related File: C:\WINDOWS\system\svchost.exe Type: Auto Services Item Name: svchost.exe Author: Unknown Related File: C:\WINDOWS\SYSTEM\SVCHOST.EXE Type: Running Processes Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.05.17 – Kaspersky 7.0.0.125 2010.05.17 Trojan-Spy.Win32.Agent.bfqs Microsoft 1.5703 2010.05.17 – [...]
Removed: C:\WINDOWS\inf\svchost.exe C:\WINDOWS\inf\csrss.exe (trojan Genome)
Malware: resume.exe Removed: C:\WINDOWS\inf\svchost.exe C:\WINDOWS\inf\csrss.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: csrss.exe Author: Unknown Related File: C:\WINDOWS\INF\CSRSS.EXE Type: Running Processes Item Name: WSALG2 Author: Microsoft® Related File: C:\WINDOWS\inf\svchost.exe Type: Auto Services Item Name: svchost.exe Author: Related File: C:\WINDOWS\INF\SVCHOST.EXE Type: Running Processes Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result [...]
Removed: adc32.dll, alggui.exe, C:\Program Files\svchost.exe, AKM Antivirus 2010 Pro.exe (Fake AV – AKM Antivirus 2010 Pro)
Malware: C:\sand-box\update.exe Removed: C:\Program Files\adc32.dll C:\Program Files\alggui.exe C:\Program Files\svchost.exe C:\Program Files\AKM Antivirus 2010 Pro\AKM Antivirus 2010 Pro.exe —————————————————————————————————————————- Detected by RegRun Warrior: Item Name: {77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02} Author: ASC – AntiSpyware Related File: C:\PROGRAM FILES\ADC32.DLL Type: Browser Helper Objects Item Name: .exe Author: Unknown Related File: C:\Program Files\alggui.exe “%1″ %* Type: Main File Extensions Item Name: AdbUpd [...]
Removed: svchost.exe (trojan Oficla)
Malware: C:\sand-box\svchost.exe Removed: C:\sand-box\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: start 1 Author: Biznes Corporation Related File: C:\SAND-BOX\SVCHOST.EXE Type: Registry Run Item Name: svchost.exe Author: Related File: C:\SAND-BOX\SVCHOST.EXE Type: Running Processes Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.22 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.04.22 – Microsoft 1.5703 [...]
Removed: tmp-3\svchost.exe (trojan Meredrop)
Malware: Flashplayer.exe Removed: C:\Documents and Settings\Administrator\Application Data\svchost.exe C:\Documents and Settings\Administrator\Application Data\tmp-3\svchost.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: windows Author: Unknown Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\TMP-3\SVCHOST.EXE Type: Registry Run Item Name: wins Author: Unknown Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\SVCHOST.EXE Type: Registry Run Item Name: winsvc32 Author: Unknown Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\\SVCHOST.EXE Type: [...]
Removed: svchost.exe
Malware: C:\sand-box\svchost.exe Removed: C:\sand-box\svchost.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.05 Trojan.Zlob.57627 Kaspersky 7.0.0.125 2010.04.05 Trojan-Spy.Win32.Webmoner.zu Microsoft 1.5605 2010.04.05 – NOD32 5001 2010.04.05 – —————————————————————————————————————————- Additional information File size: 26634 bytes MD5 : ad5f27aa4df95bbcc248805cafe8097d SHA1 : d01acc744714b2e71a987e29c8384e196313f6ea SHA256: 5d919ecd4e190146bcc5225d0a921a97e1e15f7edec082f5912442056c558ff9 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry subkeys and values: ———————————- [...]
Removed: C:\WINDOWS\ssystem32\svchost.exe
Malware: a.exe Removed: C:\WINDOWS\ssystem32\svchost.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.31 – Kaspersky 7.0.0.125 2010.03.31 Trojan.Win32.VBok.iu McAfee 5936 2010.03.30 BackDoor-CEP.svr Microsoft 1.5605 2010.03.31 VirTool:Win32/VBInject NOD32 4988 2010.03.31 Win32/Bifrose.NFJ —————————————————————————————————————————- Additional information File size: 163853 bytes MD5 : 1a6b50ce5bf5c3596b67ba067e196d06 SHA1 : 9cdbb7a488c9191e18a7e07715b7542bed9ffb9d SHA256: 214a8f82d31d13001d0a2ef611e561c859444716bf4318afd9ce356cbac88ee6 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry [...]
Removed: mssrv32.exe, 2012.exe, SVCHOST.EXE
Malware: 2012.exe Removed: c:\windows\system32\mssrv32.exe C:\Documents and Settings\Administrator\Local Settings\Temp\2012.exe C:\WINDOWS\MSSRVC\SVCHOST.EXE —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.17 Trojan.Generic.KD.4130 Kaspersky 7.0.0.125 2010.03.17 Trojan.Win32.Scar.bwgf McAfee 5923 2010.03.17 Generic BackDoor!cdw Microsoft 1.5605 2010.03.17 Backdoor:Win32/Phdet.gen!A NOD32 4953 2010.03.17 Win32/AutoRun.Agent.UP —————————————————————————————————————————- Additional information File size: 75264 bytes MD5 : 5bb1702c4501ede1b51856a38eccc238 SHA1 : 35892728f4d32465efe8e3e8332a5f9a25b20df9 SHA256: c89d1049d7ab9735588003165f23b3dc48b700d071e1bde599042af8debdea32 —————————————————————————————————————————- Installation When the program is [...]
Removed: smss.exe, C:\WINDOWS\system32:svchost.exe, Realtek.exe
Malware: flash_update.exe Removed: C:\windows\system32\drivers\smss.exe C:\WINDOWS\system32:svchost.exe C:\WINDOWS\system32\drivers\Realtek.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.09 Trojan.Downloader.AutoIT.AN Kaspersky 7.0.0.125 2010.03.09 Trojan-Downloader.Win32.AutoIt.ls McAfee 5914 2010.03.08 Generic Downloader.x!ddi Microsoft 1.5502 2010.03.09 Trojan:Win32/Comisproc NOD32 4929 2010.03.09 Win32/TrojanDownloader.Autoit.NBF —————————————————————————————————————————- Additional information File size: 209069 bytes MD5 : 3cdaa6840a4a2af61cbdb1521e20d96b SHA1 : 61e95a50ecb2aff2b968f2073268c21295eb3504 SHA256: cb2acc9f8aad7a40b269cc423aa9f359f47a32df8bc70b1e537a863bb8af934e —————————————————————————————————————————- Installation When the program is [...]
Removed: svchost.exe
Malware: C:\sand-box\a12.exe Removed: C:\Program Files\Microsoft Office\svchost.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.07 – Kaspersky 7.0.0.125 2010.03.07 Trojan-Downloader.Win32.Small.kla McAfee 5912 2010.03.06 – Microsoft 1.5502 2010.03.07 Worm:Win32/Chiviper.C NOD32 4922 2010.03.07 a variant of Win32/TrojanDownloader.Small.OUV —————————————————————————————————————————- Additional information File size: 10846 bytes MD5 : 5898801d015a61b62c9822a13bf75336 SHA1 : c38c6ecd73842115887e85804e45b7ed7f374dcf SHA256: 19501a9970b1c2fa85e70b376add83e47703e5d9a94e8e4a8ec6002e1977389a —————————————————————————————————————————- Installation When the [...]
Removed: svchost.exe, adc32.dll, alggui.exe
Malware: C:\sand-box\PC_protect.exe Removed: C:\Program Files\svchost.exe C:\Program Files\adc32.dll C:\Program Files\alggui.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.08 Suspicious:W32/Riskware!Online Kaspersky 7.0.0.125 2010.02.08 Trojan.Win32.FraudPack.akvg McAfee 5886 2010.02.08 – Microsoft 1.5406 2010.02.08 Trojan:Win32/FakeScanti NOD32 4849 2010.02.08 – —————————————————————————————————————————- Additional information File size: 1057800 bytes MD5 : 5db442825532833c145a290ea3f7c744 SHA1 : 0b538c5649f077dd5f4e9a44f386b68f2e7e1f46 SHA256: b4acad26ca4825961963017eeb8fc11da7dd87afe87968a185c280bc9d396a43 —————————————————————————————————————————- Installation When the program is executed, [...]
Removed: svchost.exe
Malware: server.exe Removed: C:\WINDOWS\system32\awServ\svchost.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.21 – Kaspersky 7.0.0.125 2010.01.21 Trojan.Win32.Refroso.aiuw McAfee 5867 2010.01.20 – Microsoft 1.5302 2010.01.20 – NOD32 4791 2010.01.20 probably a variant of Win32/Injector.AQN Symantec 20091.2.0.41 2010.01.21 – —————————————————————————————————————————- Additional information File size: 455129 bytes MD5 : 14aa4ae3008eeba8ddc6035acbbcf937 SHA1 : fb974d9a14205a36eeb75d8d5cacfece0b7eb96a SHA256: 84b41824d5c8543247d7b8c0d2db1094ef0755d43a81ffd479238a525197d0d0 —————————————————————————————————————————- [...]
Removed: svchost.exe, classapi64.dll
Malware: aser.exe Removed: C:\WINDOWS\system\svchost.exe C:\WINDOWS\system32\classapi64.dll —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.11 – Kaspersky 7.0.0.125 2010.01.12 Trojan.Win32.Buzus.cxnd McAfee 5858 2010.01.11 FakeAlert-SafetyCenter.dldr Microsoft 1.5302 2010.01.11 VirTool:Win32/VBInject.gen!CN NOD32 4762 2010.01.11 a variant of Win32/Injector.ALG Symantec 20091.2.0.41 2010.01.12 Trojan Horse —————————————————————————————————————————- Additional information File size: 294912 bytes MD5 : 7b950fe1953ed71564319c69a8f059f2 SHA1 : 96d881ee1bc60fc2efe23c0beea6c3ec9a5b8a51 SHA256: 5dd5f9b1f40c1d5aa77d9bc77b07a2b0f650e61ba4e2f7b90a1dd11beb18fc55 [...]



