Removed: rihd.pno (Trojan Oficla)
Malware: C:\sand-box\g2ccbc.exe Removed: C:\WINDOWS\system32\rihd.pno (Trojan Oficla) —————————————————————————————————————————- Detected by UnHackMe: Item Name: shell Author: Unknown Related File: Explorer.exe rundll32.exe rihd.pno eaoydsi (Trojan Oficla) Type: System.ini Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.16 Trojan:W32/Oficla.N Kaspersky 7.0.0.125 2010.04.16 Trojan.Win32.Oficla.m McAfee 5.400.0.1158 2010.04.16 Generic.dx!qyk Microsoft 1.5605 2010.04.16 Trojan:Win32/Oficla.M [...]
Removed: C:\WINDOWS\system32\kjgk.sko
Malware: C:\sand-box\balu1.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\kjgk.sko —————————————————————————————————————————- Detected by UnHackMe: Item Name: shell Author: Unknown Related File: Explorer.exe rundll32.exe kjgk.sko ibawtl Type: System.ini Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.08 Trojan.Generic.3585032 Kaspersky 7.0.0.125 2010.04.08 Trojan-Dropper.Win32.Agent.buxt Microsoft 1.5605 2010.04.08 Trojan:Win32/Oficla.M NOD32 5011 2010.04.08 Win32/Oficla.FM —————————————————————————————————————————- Additional information [...]
Removed: C:\WINDOWS\system32\YahooUpdate.exe
Malware: image001.exe —————————————————————————————————————————- Removed: C:\WINDOWS\system32\YahooUpdate.exe —————————————————————————————————————————- Detected by UnHackMe: Item Name: shell Author: Unknown Related File: Explorer.exe C:\WINDOWS\YahooUpdate.exe Type: System.ini Removal Results: Success Number of reboot: 1 —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.04.14 Trojan.Inject.HD Kaspersky 7.0.0.125 2010.04.14 – McAfee 5.400.0.1158 2010.04.14 Generic.gi Microsoft 1.5605 2010.04.14 TrojanSpy:Win32/Banker NOD32 5029 2010.04.14 a variant [...]
Removed: lywc.aoo
Malware: up.exe Removed: C:\WINDOWS\system32\lywc.aoo —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.28 Trojan.Generic.KD.4775 Kaspersky 7.0.0.125 2010.03.28 Trojan.Win32.Sasfis.ajhr McAfee 5933 2010.03.27 – Microsoft 1.5605 2010.03.28 – NOD32 4978 2010.03.26 a variant of Win32/Kryptik.DBO —————————————————————————————————————————- Additional information File size: 22528 bytes MD5 : e61c265fd436f79dbacfe94ed2bc4ddf SHA1 : ff491caba6d389556b6e885cd4d4cd9207bff847 SHA256: 15c6cbc2f60b1e16a12e8fd22c0e1d4c0ba50457e28bdfb60e622223c4e15863 —————————————————————————————————————————- Installation When the program is [...]
Removed: cbhr.uco
Malware: C:\sand-box\000.exe Removed: C:\WINDOWS\system32\cbhr.uco —————————————————————————————————————————- Classification: Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.31 – Kaspersky 7.0.0.125 2010.03.31 Trojan.Win32.Sasfis.akgp McAfee 5937 2010.03.31 – Microsoft 1.5605 2010.03.31 Trojan:Win32/Meredrop NOD32 4988 2010.03.31 Win32/Oficla.FJ —————————————————————————————————————————- Additional information File size: 20480 bytes MD5 : a770d6d6f680c42e75473ca00880ca48 SHA1 : 1c884280d13db3a23639582c2dd081c3e203df83 SHA256: d5bc3d08bca0113e8450d6c18b75314c6cd250b24486161de42bc98441a0b069 —————————————————————————————————————————- Installation When the program is executed, it creates the following registry [...]
Removed: rxms.pio
Malware: C:\sand-box\file.exe Removed: C:\WINDOWS\system32\rxms.pio —————————————————————————————————————————- Classification: 2 Antivirus Version Last Update Result F-Secure 9.0.15370.0 2010.03.26 – Kaspersky 7.0.0.125 2010.03.25 – McAfee 5931 2010.03.25 – Microsoft 1.5605 2010.03.26 TrojanDropper:Win32/Oficla.G NOD32 4975 2010.03.25 a variant of Win32/Kryptik.DHG —————————————————————————————————————————- Additional information File size: 59392 bytes MD5 : 0ef93cd209526a80e73b08820fd6d7b2 SHA1 : f008b60528aa39615bf6f1caa41a559686a46259 SHA256: 63f1421b7af2c5aefbdd5819ced8e13173eeeffc3097b6acb084850cc67e22d3 —————————————————————————————————————————- Installation When the program [...]



