Removed: taskmandb.exe, winhlp64.exe

February 3, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: C:\sand-box\setup.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\taskmandb.exe C:\Documents and Settings\Administrator\Local Settings\Temp\winhlp64.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.02.02 Gen:Trojan.Heur.Ty0@t8x83ali Kaspersky 7.0.0.125 2010.02.01 – McAfee 5879 2010.02.01 – Microsoft 1.5406 2010.02.02 – NOD32 4825 2010.02.01 – Symantec 20091.2.0.41 2010.02.02 Suspicious.Insight —————————————————————————————————————————- Additional information File size: 737280 bytes MD5 : 2fc85f45487bd6652d47ddb93b711ec4 SHA1 : 82076dce54c8a73ee2ba662f45ececf4af999851 [...]

Removed: extrac64_cab.exe, winhlp64.exe, H8SRTuthexouqxv.sys

January 26, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: C:\sand-box\load.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\extrac64_cab.exe C:\Documents and Settings\Administrator\Local Settings\Temp\winhlp64.exe C:\WINDOWS\system32\drivers\H8SRTuthexouqxv.sys —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.25 Trojan:W32/Agent.NDF Kaspersky 7.0.0.125 2010.01.25 Packed.Win32.TDSS.aa McAfee 5872 2010.01.25 – Microsoft 1.5405 2010.01.25 – NOD32 4804 2010.01.25 a variant of Win32/Kryptik.BUA Symantec 20091.2.0.41 2010.01.25 Downloader —————————————————————————————————————————- Additional information File size: 17408 bytes MD5 : [...]

Removed: extrac64_cab.exe, winhlp64.exe

January 26, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: C:\sand-box\setup.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\extrac64_cab.exe C:\Documents and Settings\Administrator\Local Settings\Temp\winhlp64.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.26 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.01.26 – McAfee 5873 2010.01.26 – Microsoft 1.5405 2010.01.26 – NOD32 4807 2010.01.26 – Symantec 20091.2.0.41 2010.01.26 – —————————————————————————————————————————- Additional information File size: 729088 bytes MD5 : 8f36fab2ab841d750ce111e7e0316a39 SHA1 : 0007d00f45596d2dc838435caa2e815b59c7c7e4 [...]

Removed: cliconfg64.exe, winhlp64.exe

January 20, 2010 by NightWatcher · Leave a Comment
Filed under: Malware 

Malware: C:\sand-box\setup.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\cliconfg64.exe C:\Documents and Settings\Administrator\Local Settings\Temp\winhlp64.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.20 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.01.20 Packed.Win32.TDSS.aa McAfee 5866 2010.01.19 FakeAlert-FQ Microsoft 1.5302 2010.01.20 Trojan:Win32/Alureon.BT NOD32 4791 2010.01.20 a variant of Win32/Kryptik.BWS Symantec 20091.2.0.41 2010.01.20 – —————————————————————————————————————————- Additional information File size: 712704 bytes MD5   : f3c06c435bec76c6e1d9a3b47b059401 SHA1  : 7c930539745b8c92c081da2894339e2501dc4d34 [...]

Removed: cls_pack.exe, winhlp64.exe

January 17, 2010 by NightWatcher · 1 Comment
Filed under: Malware 

Malware: setup.exe Removed: C:\Documents and Settings\Administrator\Local Settings\Temp\cls_pack.exe C:\Documents and Settings\Administrator\Local Settings\Temp\winhlp64.exe —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.01.16 Suspicious:W32/Malware!Gemini Kaspersky 7.0.0.125 2010.01.16 – McAfee 5863 2010.01.16 – Microsoft 1.5302 2010.01.16 – NOD32 4778 2010.01.16 – Symantec 20091.2.0.41 2010.01.16 – —————————————————————————————————————————- Additional information File size: 712704 bytes MD5 : 539cb42f77adb4614347e43ca79537fd SHA1 : 2cc54fc9806ef0da921a2a05e280b67d623bb08e [...]