Removed: C:\WINDOWS\system32\nmklo.dll, C:\WINDOWS\system32\dllcache\user32.dll, C:\WINDOWS\system32\cooper.mine (trojan Mariofev)

November 17, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: marzm.exe Removed: C:\WINDOWS\system32\nmklo.dll C:\WINDOWS\system32\dllcache\user32.dll C:\WINDOWS\system32\cooper.mine —————————————————————————————————————————- Detected manualy: NMKLO.DLL Default location: C:\WINDOWS\system32\nmklo.dll MD5: 3F7529FE29D61EA2C465B56E1AE618AF SHA1: 80859DB2 5FDADED7 57347C46 B156DB45 7196A846 File Size: 167 936 USER32.DLL Default location: C:\WINDOWS\system32\dllcache\user32.dll MD5: BBC70B9BE4BB80D2BA108B2EBABFF7EE SHA1: 254A2A8B FCD4D909 111920FC 89304032 CF7E8FD6 File Size: 578 560 Version Info: OriginalFilename: user32 FileDescription: Windows XP USER API Client DLL InternalName: user32 CompanyName: [...]

Removed: C:\WINDOWS\SYSTEM32\NMKLO.DLL Restored: C:\WINDOWS\SYSTEM32\USER32.DLL (trojan Meredrop)

June 24, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: file1.exe Removed: C:\WINDOWS\SYSTEM32\NMKLO.DLL Restored: C:\WINDOWS\SYSTEM32\USER32.DLL —————————————————————————————————————————- Detected by UnHackMe: Item Name: USER32.DLL Author: Microsoft Corporation Related File: C:\WINDOWS\SYSTEM32\USER32.DLL Type: Infected System Files Detected by RegRun Warrior: 1. Examiner: NMKLO.DLL Default location: C:\WINDOWS\SYSTEM32\NMKLO.DLL MD5: 0B7EFAD1243388CE1A3CFFD7FFD0BAA6 SHA1: 15D199A2 C1B1218A A8F6ED35 F94F4CA1 7B6994F2 File Size: 212 992 2. RegRun Reanimator: – none – 3. Multi AntiVirus scan: [...]

Removed: cbss.dll, ccl9ke.exe, nrktcvy.exe, absj.jjo, w13p1bp.exe, C:\WINDOWS\system\dwm.exe Restored: C:\WINDOWS\SYSTEM32\USER32.DLL (trojan downloader Harnig)

June 8, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: loaderadv600.exe Removed: C:\Documents and Settings\All Users\Documents\Settings\cbss.dll C:\Documents and Settings\Administrator\Local Settings\Temp\ccl9ke.exe C:\Documents and Settings\Administrator\Local Settings\Temp\nrktcvy.exe C:\WINDOWS\system32\absj.jjo C:\Documents and Settings\Administrator\Local Settings\Temp\w13p1bp.exe C:\WINDOWS\system\dwm.exe Restored: C:\WINDOWS\SYSTEM32\USER32.DLL —————————————————————————————————————————- Detected by UnHackMe: Item Name: cbssreg Author: Related File: C:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\SETTINGS\CBSS.DLL Type: Winlogon Notification Item Name: khfy2n Author: Unknown Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\CCL9KE.EXE Type: Explorer Run Item Name: 12370 Author: [...]

Removed: nmklo.dll Restored: user32.DLL (trojan Pinit)

May 19, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: mic.exe Removed: C:\WINDOWS\system32\nmklo.dll Restored: C:\WINDOWS\system32\user32.DLL —————————————————————————————————————————- Detected by UnHackMe: NMKLO.DLL Default location: C:\sand-box\files_added\nmklo.dll MD5: 4C3FE9D49B49097D8BE58A94BB140BC5 SHA1: CDCF4F72 84A95DF8 EDE8EEEF 1A142DB7 4FBDC123 File Size: 98 304 USER32.DLL Default location: C:\sand-box\files_added\user32.dll MD5: D8C58E94A30C552FE17BA86B56F9E9E8 SHA1: ED429EB0 9BE1CE20 60E0BFE2 BE0FFA17 F943E7FD File Size: 578 560 Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update [...]

Malware: so1.exe

March 1, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: so1.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.01 Trojan.Generic.KD.143 Kaspersky 7.0.0.125 2010.03.01 Worm.Win32.Pinit.jr McAfee 5906 2010.02.28 Generic.dx!okm Microsoft 1.5502 2010.02.28 VirTool:Win32/Obfuscator.HY NOD32 4903 2010.02.28 a variant of Win32/Kryptik.COP —————————————————————————————————————————- Additional information File size: 219648 bytes MD5 : 0c27ab86792d213cd6870f21b67b3489 SHA1 : 8c7416f2533f2304cf6c5e28f63a8715d1a50554 SHA256: 89bd9eb833da845d4eb312b07b656e1992c740b54379b86e2b6131586c48473a —————————————————————————————————————————- Installation When the program is executed, it [...]

Malware: load.exe

February 25, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: load.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.24 – Kaspersky 7.0.0.125 2010.02.24 Backdoor.Win32.Small.iys McAfee 5901 2010.02.23 – Microsoft 1.5406 2010.02.24 Worm:Win32/Mariofev.A NOD32 4892 2010.02.24 Win32/Pinit.AF Symantec 20091.2.0.41 2010.02.24 Suspicious.Insight —————————————————————————————————————————- Additional information File size: 265728 bytes MD5 : 70518439511d549ee65f6d45e008b6eb SHA1 : c4759c639bece7900fff2fe0c77ae83aa4f90dc0 SHA256: a741631213bdc0e2514a1989e25e807eee306cfbbdd876036f9b7cf105762fd4 —————————————————————————————————————————- Installation When the program is executed, [...]