STAGE2.EXE – Unclassified Malware

Alex NightWatcher: Solved! Fix it immediately! STAGE2.EXE – Unclassified Malware removal STAGE2.EXE size: 146396 bytes STAGE2.EXE hash: 99CE91F174101BCD7E2F1F043095ADC1 Created files: %Program Files Common%\System\Taskbar.exe %TEMP%\Stage1.exe %TEMP%\Stage2.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Update: %Program Files Common%\System\Taskbar.exe Detected by UnHackMe: STAGE2.EXE Default location: %TEMP%\STAGE2.EXE Dropper information: MD5: 2c85fea63c2cf4ae88f948f6e116f104 File size: 191260 bytes Remove it now! Recommended: UnHackMe anti-rootkit and…

Continue reading

ALG.EXE – Trojan Darkshell

Alex NightWatcher: Solved! Fix it immediately! ALG.EXE – Trojan Darkshell removal File MD5 Virus Alias ALG.EXE bf3b2b4634e678ae6176a3bf77b14fb5 Trojan Darkshell ALG.EXE bf3b2b4634e678ae6176a3bf77b14fb5 Trojan Eldorado ALG.EXE bf3b2b4634e678ae6176a3bf77b14fb5 Trojan Downloader ALG.EXE bf3b2b4634e678ae6176a3bf77b14fb5 Virus Part ALG.EXE bf3b2b4634e678ae6176a3bf77b14fb5 Trojan Agent ALG.EXE bf3b2b4634e678ae6176a3bf77b14fb5 Trojan Small ALG.EXE size: 36680 bytes ALG.EXE hash: BF3B2B4634E678AE6176A3BF77B14FB5 Created files: C:\alg.exe C:\config.exe C:\conime.exe Detected by UnHackMe: ALG.EXE…

Continue reading

FIRUTVUZLICF.EXE – Trojan Wigon

Alex NightWatcher: Solved! Fix it immediately! FIRUTVUZLICF.EXE – Trojan Wigon removal File MD5 Virus Alias FIRUTVUZLICF.EXE 432b67ce1031a1727368db09ba1c21fc Trojan Wigon FIRUTVUZLICF.EXE 432b67ce1031a1727368db09ba1c21fc Trojan XPACK FIRUTVUZLICF.EXE 432b67ce1031a1727368db09ba1c21fc Trojan Generic FIRUTVUZLICF.EXE 432b67ce1031a1727368db09ba1c21fc Trojan Downloader FIRUTVUZLICF.EXE 432b67ce1031a1727368db09ba1c21fc Worm AMN FIRUTVUZLICF.EXE 432b67ce1031a1727368db09ba1c21fc Trojan Kazy FIRUTVUZLICF.EXE size: 44032 bytes FIRUTVUZLICF.EXE hash: 432B67CE1031A1727368DB09BA1C21FC Created files: %UserProfile%\firutvuzlicf.exe Autostart registry keys: HKCU\Software\Microsoft\Windows\CurrentVersion\run\firutvuzlicf: %WinDir%\System32\config\Systemprofile\firutvuzlicf.exe Detected…

Continue reading

STAGE1.EXE – Trojan Artemis

Alex NightWatcher: Solved! Fix it immediately! STAGE1.EXE – Trojan Artemis removal File MD5 Virus Alias STAGE1.EXE 05646977e67b86ba03a8d2f6e0791db2 Trojan Artemis STAGE1.EXE 05646977e67b86ba03a8d2f6e0791db2 Trojan Eldorado STAGE1.EXE 05646977e67b86ba03a8d2f6e0791db2 Backdoor RBot STAGE1.EXE 05646977e67b86ba03a8d2f6e0791db2 Trojan Agent STAGE1.EXE 05646977e67b86ba03a8d2f6e0791db2 Trojan Jorik STAGE1.EXE 05646977e67b86ba03a8d2f6e0791db2 Backdoor IRCBot STAGE1.EXE size: 83456 bytes STAGE1.EXE hash: 05646977E67B86BA03A8D2F6E0791DB2 Created files: %Program Files Common%\System\Taskbar.exe %TEMP%\Stage1.exe %TEMP%\Stage2.exe Autostart registry…

Continue reading

TASKMGR.EXE – Unknown

Alex NightWatcher: Solved! Fix it immediately! TASKMGR.EXE – Unknown removal TASKMGR.EXE size: 45297 bytes TASKMGR.EXE hash: 6E21373DB9A00EE353E491296F19B068 Created files: %SysDir%\mydev.dll %TEMP%\taskmgr.exe Detected by UnHackMe: TASKMGR.EXE Default location: %TEMP%\TASKMGR.EXE Dropper information: MD5: 6e21373db9a00ee353e491296f19b068 File size: 45297 bytes Remove it now! Recommended: UnHackMe anti-rootkit and anti-malware Premium software: RegRun Security Suite (Good choice for removal and protection)

CONIME.EXE – Trojan Darkshell

Alex NightWatcher: Solved! Fix it immediately! CONIME.EXE – Trojan Darkshell removal File MD5 Virus Alias CONIME.EXE 3446c15d842772f8b9282577620ac7d0 Trojan Darkshell CONIME.EXE 3446c15d842772f8b9282577620ac7d0 Trojan Eldorado CONIME.EXE 3446c15d842772f8b9282577620ac7d0 Trojan Downloader CONIME.EXE 3446c15d842772f8b9282577620ac7d0 Virus Part CONIME.EXE 3446c15d842772f8b9282577620ac7d0 Trojan Agent CONIME.EXE 3446c15d842772f8b9282577620ac7d0 Trojan Small CONIME.EXE size: 36680 bytes CONIME.EXE hash: 3446C15D842772F8B9282577620AC7D0 Created files: C:\alg.exe C:\config.exe C:\conime.exe Detected by UnHackMe: CONIME.EXE…

Continue reading

NTHID.SYS – Trojan Agent

Alex NightWatcher: Solved! Fix it immediately! NTHID.SYS – Trojan Agent removal File MD5 Virus Alias NTHID.SYS 4a15af4ff018f73e7b734589cd50ea89 Trojan Agent NTHID.SYS 4a15af4ff018f73e7b734589cd50ea89 Trojan Generic NTHID.SYS 4a15af4ff018f73e7b734589cd50ea89 Trojan Downloader NTHID.SYS 4a15af4ff018f73e7b734589cd50ea89 Worm Autorun NTHID.SYS 4a15af4ff018f73e7b734589cd50ea89 Trojan Small NTHID.SYS size: 5008 bytes NTHID.SYS hash: 4A15AF4FF018F73E7B734589CD50EA89 Created files: %TEMP%\Expor.exe %TEMP%\NtHid.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\bits\Start: 02000000 HKLM\System\CurrentControlSet\Services\NtHid\Type: 01000000 HKLM\System\CurrentControlSet\Services\NtHid\Start: 03000000…

Continue reading

SVCHOST.EXE – Trojan Artemis

Alex NightWatcher: Solved! Fix it immediately! SVCHOST.EXE – Trojan Artemis removal File MD5 Virus Alias SVCHOST.EXE 175f151b96deec42081aa4d331883fcc Trojan Artemis SVCHOST.EXE 175f151b96deec42081aa4d331883fcc Trojan SuspiciousFile SVCHOST.EXE 175f151b96deec42081aa4d331883fcc Trojan Generic SVCHOST.EXE 175f151b96deec42081aa4d331883fcc Trojan Click SVCHOST.EXE size: 281088 bytes SVCHOST.EXE hash: 175F151B96DEEC42081AA4D331883FCC Created files: %UserProfile%\My Documents\Windows\AppLoc\svchost.exe Autostart registry keys: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Google: %WinDir%\System32\config\Systemprofile\My Documents\Windows\AppLoc\svchost.exe Detected by UnHackMe: SVCHOST.EXE Default location: %USERPROFILE%\MY…

Continue reading

CRACKS.EXE – Virus Part

Alex NightWatcher: Solved! Fix it immediately! CRACKS.EXE – Virus Part removal File MD5 Virus Alias CRACKS.EXE fc1cb491c700fc3e7630637220c6d16a Virus Part CRACKS.EXE size: 691711 bytes CRACKS.EXE hash: FC1CB491C700FC3E7630637220C6D16A Created files: %TEMP%\7ZipSfx.000\crackS.exe %TEMP%\7ZipSfx.000\rsd_en_5.exe Detected by UnHackMe: CRACKS.EXE Default location: %TEMP%\7ZIPSFX.000\CRACKS.EXE Dropper information: MD5: 65ca0097adcb64a2124f79dd82a8b7cb File size: 2148813 bytes Remove it now! Recommended: UnHackMe anti-rootkit and anti-malware Premium software:…

Continue reading

EXPLORER.COM – Trojan Delf

Alex NightWatcher: Solved! Fix it immediately! EXPLORER.COM – Trojan Delf removal File MD5 Virus Alias EXPLORER.COM 1dd5756ed018f341dbd970933e5eadd1 Trojan Delf EXPLORER.COM 1dd5756ed018f341dbd970933e5eadd1 Trojan Generic EXPLORER.COM 1dd5756ed018f341dbd970933e5eadd1 Trojan Eldorado EXPLORER.COM 1dd5756ed018f341dbd970933e5eadd1 Trojan Downloader EXPLORER.COM 1dd5756ed018f341dbd970933e5eadd1 Trojan CI EXPLORER.COM 1dd5756ed018f341dbd970933e5eadd1 Trojan Delphi EXPLORER.COM size: 23552 bytes EXPLORER.COM hash: 1DD5756ED018F341DBD970933E5EADD1 Created files: %WinDir%\explorer.com Autostart registry keys: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: explorer.com…

Continue reading

CRYPTO.UTIL._COUNTER.PYD – Unknown

Alex NightWatcher: Solved! Fix it immediately! CRYPTO.UTIL._COUNTER.PYD – Unknown removal CRYPTO.UTIL._COUNTER.PYD size: 11264 bytes CRYPTO.UTIL._COUNTER.PYD hash: D30952A077FC497261A35B2584A3A05C Created files: %TEMP%\_MEI140442\bz2.pyd %TEMP%\_MEI140442\Crypto.Cipher.AES.pyd %TEMP%\_MEI140442\Crypto.Hash.SHA256.pyd %TEMP%\_MEI140442\Crypto.Random.OSRNG.winrandom.pyd %TEMP%\_MEI140442\Crypto.Util._counter.pyd %TEMP%\_MEI140442\eggs\progressbar-2.3-py2.7.egg %TEMP%\_MEI140442\msvcm90.dll %TEMP%\_MEI140442\msvcp90.dll %TEMP%\_MEI140442\msvcr90.dll %TEMP%\_MEI140442\pyexpat.pyd %TEMP%\_MEI140442\python27.dll %TEMP%\_MEI140442\select.pyd %TEMP%\_MEI140442\tcl85.dll %TEMP%\_MEI140442\tk85.dll %TEMP%\_MEI140442\unicodedata.pyd %TEMP%\_MEI140442\_ctypes.pyd %TEMP%\_MEI140442\_hashlib.pyd %TEMP%\_MEI140442\_MEI\tcl\auto.tcl %TEMP%\_MEI140442\_MEI\tcl\clock.tcl %TEMP%\_MEI140442\_MEI\tcl\history.tcl %TEMP%\_MEI140442\_MEI\tcl\init.tcl %TEMP%\_MEI140442\_MEI\tcl\package.tcl %TEMP%\_MEI140442\_MEI\tcl\parray.tcl %TEMP%\_MEI140442\_MEI\tcl\safe.tcl %TEMP%\_MEI140442\_MEI\tcl\tclIndex %TEMP%\_MEI140442\_MEI\tcl\tm.tcl %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Adak %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Anchorage %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Anguilla %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Antigua %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Araguaina %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Aruba %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Asuncion %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Atikokan %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Atka %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Bahia…

Continue reading

SS.EXE – Trojan Barys

Alex NightWatcher: Solved! Fix it immediately! SS.EXE – Trojan Barys removal File MD5 Virus Alias SS.EXE 2829cb96c4c3bae7d9b2812b8afda8de Trojan Barys SS.EXE 2829cb96c4c3bae7d9b2812b8afda8de Trojan Generic SS.EXE 2829cb96c4c3bae7d9b2812b8afda8de Trojan Agent SS.EXE 2829cb96c4c3bae7d9b2812b8afda8de Trojan Jorik SS.EXE size: 25088 bytes SS.EXE hash: 2829CB96C4C3BAE7D9B2812B8AFDA8DE Created files: %UserProfile%\ss.exe %UserProfile%\winlogon.exe %SysDir%\crrss.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\crrss: %WinDir%\System32\crrss.exe HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: %WinDir%\System32\userinit.exe,%WinDir%\System32\crrss.exe HKCU\Software\Microsoft\Windows\CurrentVersion\Run\winlogon: %WinDir%\System32\config\Systemprofile\winlogon.exe HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell:…

Continue reading

SVCHOST.EXE – Trojan SuspiciousFile

Alex NightWatcher: Solved! Fix it immediately! SVCHOST.EXE – Trojan SuspiciousFile removal File MD5 Virus Alias SVCHOST.EXE 79b21e07cf2bf741275f7191ec7f33f2 Trojan SuspiciousFile SVCHOST.EXE 79b21e07cf2bf741275f7191ec7f33f2 Trojan Generic SVCHOST.EXE 79b21e07cf2bf741275f7191ec7f33f2 Trojan CI SVCHOST.EXE 79b21e07cf2bf741275f7191ec7f33f2 Trojan Agent SVCHOST.EXE size: 62464 bytes SVCHOST.EXE hash: 79B21E07CF2BF741275F7191EC7F33F2 Created files: %WinDir%\svchost.exe Autostart registry keys: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost.exe: 79B21E07CF2BF741275F7191EC7F33F2.EXE Detected by UnHackMe: SVCHOST.EXE Default location: %WinDir%\SVCHOST.EXE Dropper information:…

Continue reading

SERVOS.EXE – Trojan Delf

Alex NightWatcher: Solved! Fix it immediately! SERVOS.EXE – Trojan Delf removal File MD5 Virus Alias SERVOS.EXE 5cd1807d8a2aa57058bd4d77988a6b5b Trojan Delf SERVOS.EXE 5cd1807d8a2aa57058bd4d77988a6b5b Trojan Generic SERVOS.EXE 5cd1807d8a2aa57058bd4d77988a6b5b Trojan Tibia SERVOS.EXE 5cd1807d8a2aa57058bd4d77988a6b5b Adware InstallCore SERVOS.EXE 5cd1807d8a2aa57058bd4d77988a6b5b Trojan Crypt SERVOS.EXE size: 40448 bytes SERVOS.EXE hash: 5CD1807D8A2AA57058BD4D77988A6B5B Created files: %WinDir%\servos.exe %TEMP%\2E1BC5.dmp Autostart registry keys: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: explorer.exe, servos.exe Detected by…

Continue reading

EXPOR.EXE – Worm Autorun

Alex NightWatcher: Solved! Fix it immediately! EXPOR.EXE – Worm Autorun removal File MD5 Virus Alias EXPOR.EXE 4a8cc6f40bbb9dbb03bfd7943790086e Worm Autorun EXPOR.EXE 4a8cc6f40bbb9dbb03bfd7943790086e Trojan SuspiciousFile EXPOR.EXE 4a8cc6f40bbb9dbb03bfd7943790086e Trojan Generic EXPOR.EXE 4a8cc6f40bbb9dbb03bfd7943790086e Trojan Hllw EXPOR.EXE 4a8cc6f40bbb9dbb03bfd7943790086e Trojan Downloader EXPOR.EXE 4a8cc6f40bbb9dbb03bfd7943790086e Trojan Agent EXPOR.EXE size: 26112 bytes EXPOR.EXE hash: 4A8CC6F40BBB9DBB03BFD7943790086E Created files: %TEMP%\Expor.exe %TEMP%\NtHid.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\bits\Start: 02000000…

Continue reading

RSD_EN_5.EXE – Trojan Artemis

Alex NightWatcher: Solved! Fix it immediately! RSD_EN_5.EXE – Trojan Artemis removal File MD5 Virus Alias RSD_EN_5.EXE 89c7bf7194282514f93328444aed3718 Trojan Artemis RSD_EN_5.EXE 89c7bf7194282514f93328444aed3718 Trojan SuspiciousFile RSD_EN_5.EXE 89c7bf7194282514f93328444aed3718 Trojan Generic RSD_EN_5.EXE 89c7bf7194282514f93328444aed3718 Trojan Jorik RSD_EN_5.EXE size: 1624638 bytes RSD_EN_5.EXE hash: 89C7BF7194282514F93328444AED3718 Created files: %TEMP%\7ZipSfx.000\crackS.exe %TEMP%\7ZipSfx.000\rsd_en_5.exe Detected by UnHackMe: RSD_EN_5.EXE Default location: %TEMP%\7ZIPSFX.000\RSD_EN_5.EXE Dropper information: MD5: 65ca0097adcb64a2124f79dd82a8b7cb File size:…

Continue reading

CRYPTO.CIPHER.AES.PYD – Unknown

Alex NightWatcher: Solved! Fix it immediately! CRYPTO.CIPHER.AES.PYD – Unknown removal CRYPTO.CIPHER.AES.PYD size: 31744 bytes CRYPTO.CIPHER.AES.PYD hash: CF853A26665365AA0BD5130480CD1260 Created files: %TEMP%\_MEI140442\bz2.pyd %TEMP%\_MEI140442\Crypto.Cipher.AES.pyd %TEMP%\_MEI140442\Crypto.Hash.SHA256.pyd %TEMP%\_MEI140442\Crypto.Random.OSRNG.winrandom.pyd %TEMP%\_MEI140442\Crypto.Util._counter.pyd %TEMP%\_MEI140442\eggs\progressbar-2.3-py2.7.egg %TEMP%\_MEI140442\msvcm90.dll %TEMP%\_MEI140442\msvcp90.dll %TEMP%\_MEI140442\msvcr90.dll %TEMP%\_MEI140442\pyexpat.pyd %TEMP%\_MEI140442\python27.dll %TEMP%\_MEI140442\select.pyd %TEMP%\_MEI140442\tcl85.dll %TEMP%\_MEI140442\tk85.dll %TEMP%\_MEI140442\unicodedata.pyd %TEMP%\_MEI140442\_ctypes.pyd %TEMP%\_MEI140442\_hashlib.pyd %TEMP%\_MEI140442\_MEI\tcl\auto.tcl %TEMP%\_MEI140442\_MEI\tcl\clock.tcl %TEMP%\_MEI140442\_MEI\tcl\history.tcl %TEMP%\_MEI140442\_MEI\tcl\init.tcl %TEMP%\_MEI140442\_MEI\tcl\package.tcl %TEMP%\_MEI140442\_MEI\tcl\parray.tcl %TEMP%\_MEI140442\_MEI\tcl\safe.tcl %TEMP%\_MEI140442\_MEI\tcl\tclIndex %TEMP%\_MEI140442\_MEI\tcl\tm.tcl %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Adak %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Anchorage %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Anguilla %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Antigua %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Araguaina %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Aruba %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Asuncion %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Atikokan %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Atka %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Bahia…

Continue reading

OCSETUPHLP.DLL – Adware OpenCandy

Alex NightWatcher: Solved! Fix it immediately! OCSETUPHLP.DLL – Adware OpenCandy removal File MD5 Virus Alias OCSETUPHLP.DLL 02593a11c844952bb19a03f8c2b5f879 Adware OpenCandy OCSETUPHLP.DLL size: 807280 bytes OCSETUPHLP.DLL hash: 02593A11C844952BB19A03F8C2B5F879 Created files: %TEMP%\is-2CECQ.tmp\OCSetupHlp.dll Detected by UnHackMe: OCSETUPHLP.DLL Default location: %TEMP%\IS-2CECQ.TMP\OCSETUPHLP.DLL Dropper information: MD5: 81c8989844195f1c0ea230504daf92d9 File size: 3616752 bytes Remove it now! Recommended: UnHackMe anti-rootkit and anti-malware Premium software: RegRun…

Continue reading

JPEG.DLL – Unclassified Malware

Alex NightWatcher: Solved! Fix it immediately! JPEG.DLL – Unclassified Malware removal JPEG.DLL size: 106496 bytes JPEG.DLL hash: 0DA8449291B80AAC6C6F7E356D14BA36 Created files: %TEMP%\~vis0000\English.vlg %TEMP%\~vis0000\jpeg.dll %TEMP%\~vis0000\miscdata.xyz %TEMP%\~vis0000\rebootnt.exe %TEMP%\~vis0000\uninst32.exe %TEMP%\~vis0000\vise32ex.dll Detected by UnHackMe: JPEG.DLL Default location: %TEMP%\~VIS0000\JPEG.DLL Dropper information: MD5: b3169fed29953efc89edbaf545ce7bf9 File size: 4036087 bytes Remove it now! Recommended: UnHackMe anti-rootkit and anti-malware Premium software: RegRun Security Suite (Good…

Continue reading

SSAM.EXE – Trojan Artemis

Alex NightWatcher: Solved! Fix it immediately! SSAM.EXE – Trojan Artemis removal File MD5 Virus Alias SSAM.EXE 49d7663d5ed07e6a63789cd9cd305791 Trojan Artemis SSAM.EXE 49d7663d5ed07e6a63789cd9cd305791 Trojan SuspiciousFile SSAM.EXE 49d7663d5ed07e6a63789cd9cd305791 Trojan Generic SSAM.EXE size: 36864 bytes SSAM.EXE hash: 49D7663D5ED07E6A63789CD9CD305791 Created files: %SysDir%\Ssam.exe %SysDir%\Ssan.exe Autostart registry keys: HKLM\System\CurrentControlSet\Services\SampleService\Type: 10000000 HKLM\System\CurrentControlSet\Services\SampleService\Start: 02000000 HKLM\System\CurrentControlSet\Services\SampleService\ErrorControl: 01000000 HKLM\System\CurrentControlSet\Services\SampleService\DisplayName: Sample Service HKLM\System\CurrentControlSet\Services\SampleService\ImagePath: %WinDir%\System32\Ssan.exe HKLM\System\CurrentControlSet\Services\SampleService\ObjectName: LocalSystem Detected…

Continue reading

CRYPTO.RANDOM.OSRNG.WINRANDOM.PYD – Unknown

Alex NightWatcher: Solved! Fix it immediately! CRYPTO.RANDOM.OSRNG.WINRANDOM.PYD – Unknown removal CRYPTO.RANDOM.OSRNG.WINRANDOM.PYD size: 10752 bytes CRYPTO.RANDOM.OSRNG.WINRANDOM.PYD hash: 8D533272469BAD4AD1F8A1DAA33C32FA Created files: %TEMP%\_MEI140442\bz2.pyd %TEMP%\_MEI140442\Crypto.Cipher.AES.pyd %TEMP%\_MEI140442\Crypto.Hash.SHA256.pyd %TEMP%\_MEI140442\Crypto.Random.OSRNG.winrandom.pyd %TEMP%\_MEI140442\Crypto.Util._counter.pyd %TEMP%\_MEI140442\eggs\progressbar-2.3-py2.7.egg %TEMP%\_MEI140442\msvcm90.dll %TEMP%\_MEI140442\msvcp90.dll %TEMP%\_MEI140442\msvcr90.dll %TEMP%\_MEI140442\pyexpat.pyd %TEMP%\_MEI140442\python27.dll %TEMP%\_MEI140442\select.pyd %TEMP%\_MEI140442\tcl85.dll %TEMP%\_MEI140442\tk85.dll %TEMP%\_MEI140442\unicodedata.pyd %TEMP%\_MEI140442\_ctypes.pyd %TEMP%\_MEI140442\_hashlib.pyd %TEMP%\_MEI140442\_MEI\tcl\auto.tcl %TEMP%\_MEI140442\_MEI\tcl\clock.tcl %TEMP%\_MEI140442\_MEI\tcl\history.tcl %TEMP%\_MEI140442\_MEI\tcl\init.tcl %TEMP%\_MEI140442\_MEI\tcl\package.tcl %TEMP%\_MEI140442\_MEI\tcl\parray.tcl %TEMP%\_MEI140442\_MEI\tcl\safe.tcl %TEMP%\_MEI140442\_MEI\tcl\tclIndex %TEMP%\_MEI140442\_MEI\tcl\tm.tcl %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Adak %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Anchorage %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Anguilla %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Antigua %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Araguaina %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Aruba %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Asuncion %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Atikokan %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Atka %TEMP%\_MEI140442\_MEI\tcl\tzdata\America\Bahia…

Continue reading

FYHADFIBODAC.EXE – Trojan Downloader

Alex NightWatcher: Solved! Fix it immediately! FYHADFIBODAC.EXE – Trojan Downloader removal File MD5 Virus Alias FYHADFIBODAC.EXE ec0034740461f874f24959040e181875 Trojan Downloader FYHADFIBODAC.EXE ec0034740461f874f24959040e181875 Trojan XPACK FYHADFIBODAC.EXE ec0034740461f874f24959040e181875 Trojan Generic FYHADFIBODAC.EXE ec0034740461f874f24959040e181875 Trojan Agent FYHADFIBODAC.EXE ec0034740461f874f24959040e181875 Trojan ZBot FYHADFIBODAC.EXE ec0034740461f874f24959040e181875 Trojan Kryptik FYHADFIBODAC.EXE size: 38864 bytes FYHADFIBODAC.EXE hash: EC0034740461F874F24959040E181875 Created files: %UserProfile%\fyhadfibodac.exe Autostart registry keys: HKCU\Software\Microsoft\Windows\CurrentVersion\run\fyhadfibodac: %WinDir%\System32\config\Systemprofile\fyhadfibodac.exe Detected…

Continue reading

VXS.DLL – Unknown

Alex NightWatcher: Solved! Fix it immediately! VXS.DLL – Unknown removal VXS.DLL size: 28783 bytes VXS.DLL hash: 8AC88DBF7C54D2C28F0B033203EAABC0 Created files: %TEMP%\pdk-USER\04a938823668c652aef77ba79a274400\Service.dll %TEMP%\pdk-USER\04bcde2df1201d4ca27b3d15bc70f061\File.dll %TEMP%\pdk-USER\126606fc960394fe3e984ab0034deece\Base64.dll %TEMP%\pdk-USER\2320369d134a6ac3fb09bed5cc996e0d\Registry.dll %TEMP%\pdk-USER\26a4ddfe38ff31aec0b31910583056a7\HiRes.dll %TEMP%\pdk-USER\2c021404158e6dce22d4fbdc75299e15\Socket6.dll %TEMP%\pdk-USER\2fe8ff4bfa5c11ea07d1b72d581c532c\Socket.dll %TEMP%\pdk-USER\43784a154a54e492d5c9fc33d757a4f6\ReadKey.dll %TEMP%\pdk-USER\479fd221bbb84ecac02480d36541df3e\Zlib.dll %TEMP%\pdk-USER\581ddb8f24bcc94b3c7c92f0a066849e\Util.dll %TEMP%\pdk-USER\633e1eb2f74ee89a04c5fe0da86bb007\API.dll %TEMP%\pdk-USER\76a014d4d33e7742fea967000b9f56df\Win32.dll %TEMP%\pdk-USER\84f0a472c2993eaf2c261c88c47b256c\IO.dll %TEMP%\pdk-USER\8ac88dbf7c54d2c28f0b033203eaabc0\vxs.dll %TEMP%\pdk-USER\9d737b45a76be5e2cce65d9ae228fda4\AdminMisc.dll %TEMP%\pdk-USER\ae80716afdae2cf86864613462720577\Cwd.dll %TEMP%\pdk-USER\d6fec475513d165261d38743a490dfc1\perl58.dll %TEMP%\pdk-USER\d97efd380be345656a7c568479bf8897\Fcntl.dll %TEMP%\pdk-USER\dad8a2781d545b007729f2cb48fd26bf\DNS.dll %TEMP%\pdk-USER\e00cd61a82f12186df5e4de4b75a822d\Registry.dll %TEMP%\pdk-USER\e838a13d00b4a94a2007c73b57ad70dc\Calc.dll %TEMP%\pdk-USER\ea8ed9772b76a525d50cde8448090219\WinError.dll %TEMP%\pdk-USER\f8a7cb4589abf2df9cade9d06eb78fe3\Ver.dll %TEMP%\pdk-USER-10332\MSVCR70.dll Detected by UnHackMe: VXS.DLL Default location: %TEMP%\PDK-USER\8AC88DBF7C54D2C28F0B033203EAABC0\VXS.DLL Dropper information: MD5: ab89e67456407e0292a1e6a169f6b4f5 File…

Continue reading

K.J_121021E.EXE – Unknown

Alex NightWatcher: Solved! Fix it immediately! K.J_121021E.EXE – Unknown removal K.J_121021E.EXE size: 36633463 bytes K.J_121021E.EXE hash: 0C32089BE4EBE827632A1F09CD06798C Created files: %TEMP%\7ZipSfx.000\Ac.vbs %TEMP%\7ZipSfx.000\Bios\Bios.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\bootmgr.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\data\bootmgr\bootmgr %TEMP%\7ZipSfx.000\BIOS_Emulator\data\bootmgr_default\bootmgr %TEMP%\7ZipSfx.000\BIOS_Emulator\data\Install_files_open\grldr %TEMP%\7ZipSfx.000\BIOS_Emulator\data\Install_files_open\SLIC.BIN %TEMP%\7ZipSfx.000\BIOS_Emulator\data\Install_files_vfd\grldr %TEMP%\7ZipSfx.000\BIOS_Emulator\data\Install_files_vfd\SLIC.IMG %TEMP%\7ZipSfx.000\BIOS_Emulator\data\Install_files_vista\grldr %TEMP%\7ZipSfx.000\BIOS_Emulator\data\Install_files_w7\grldr %TEMP%\7ZipSfx.000\BIOS_Emulator\data\Install_files_w7open\grldr %TEMP%\7ZipSfx.000\BIOS_Emulator\Install_open.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\Install_vfd.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\Install_vista.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\Install_w7.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\Install_w7A.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\Install_w7open.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\rundll32.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\Successful.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\Uninstall.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\UninstallA.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\WatermarkX64.vbs %TEMP%\7ZipSfx.000\BIOS_Emulator\WatermarkX86.vbs %TEMP%\7ZipSfx.000\ChkWin.vbs %TEMP%\7ZipSfx.000\DesktopGadgets.vbs %TEMP%\7ZipSfx.000\Embedded.vbs %TEMP%\7ZipSfx.000\Embedded_k.vbs %TEMP%\7ZipSfx.000\FSCapture\FSCapture.vbs %TEMP%\7ZipSfx.000\FSCapture\FSCapture2.vbs %TEMP%\7ZipSfx.000\hs_message.vbs %TEMP%\7ZipSfx.000\KJ_e.apm %TEMP%\7ZipSfx.000\KMService.vbs %TEMP%\7ZipSfx.000\ospp.vbs %TEMP%\7ZipSfx.000\Pirate\Failed.apm %TEMP%\7ZipSfx.000\Pirate\Install.vbs…

Continue reading

NCHSETUP.EXE – Unknown

Alex NightWatcher: Solved! Fix it immediately! NCHSETUP.EXE – Unknown removal NCHSETUP.EXE size: 1826328 bytes NCHSETUP.EXE hash: 09B849CE5F1F5ABD5A611034A44FCB70 Created files: %TEMP%\n1s\nchdata.cab %TEMP%\n1s\nchsetup.cab %TEMP%\n1s\nchsetup.exe Detected by UnHackMe: NCHSETUP.EXE Default location: %TEMP%\N1S\NCHSETUP.EXE Dropper information: MD5: d5dbce072cb376971b0bcbd51f29a6b3 File size: 1528344 bytes Remove it now! Recommended: UnHackMe anti-rootkit and anti-malware Premium software: RegRun Security Suite (Good choice for removal and…

Continue reading

TN7.EXE – Worm Autoit

Alex NightWatcher: Solved! Fix it immediately! TN7.EXE – Worm Autoit removal File MD5 Virus Alias TN7.EXE d2c5b9c42616992e8a0d91964a9762ee Worm Autoit TN7.EXE d2c5b9c42616992e8a0d91964a9762ee Trojan Generic TN7.EXE d2c5b9c42616992e8a0d91964a9762ee Trojan Chifrax TN7.EXE d2c5b9c42616992e8a0d91964a9762ee Trojan CI TN7.EXE d2c5b9c42616992e8a0d91964a9762ee Worm AMN TN7.EXE d2c5b9c42616992e8a0d91964a9762ee Backdoor Poison TN7.EXE size: 865711 bytes TN7.EXE hash: D2C5B9C42616992E8A0D91964A9762EE Created files: %TEMP%\AutoIt3.exe %TEMP%\data\Microsoft.vbs %TEMP%\tn7.exe Autostart registry keys: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate:…

Continue reading

RFMUWFD.DLL – Trojan Kazy

Alex NightWatcher: Solved! Fix it immediately! RFMUWFD.DLL – Trojan Kazy removal File MD5 Virus Alias RFMUWFD.DLL 056d33909dc421dfde5a4a810e35e0d7 Trojan Kazy RFMUWFD.DLL 056d33909dc421dfde5a4a810e35e0d7 Trojan SuspiciousFile RFMUWFD.DLL 056d33909dc421dfde5a4a810e35e0d7 Trojan Artemis RFMUWFD.DLL 056d33909dc421dfde5a4a810e35e0d7 Trojan OnLineGames RFMUWFD.DLL 056d33909dc421dfde5a4a810e35e0d7 Trojan Agent RFMUWFD.DLL size: 81920 bytes RFMUWFD.DLL hash: 056D33909DC421DFDE5A4A810E35E0D7 Created files: %SysDir%\Rfmuwfd.dll %Common AppData%\Microsoft\Dr Watson\user.dmp Autostart registry keys: HKLM\System\CurrentControlSet\Services\MediagCenterm\Type: 10000000 HKLM\System\CurrentControlSet\Services\MediagCenterm\Start: 02000000…

Continue reading

MSSRV32.EXE – Trojan Downloader

Alex NightWatcher: Solved! Fix it immediately! MSSRV32.EXE – Trojan Downloader removal File MD5 Virus Alias MSSRV32.EXE 97fe565d2160dd4e834f897b77cabf8f Trojan Downloader MSSRV32.EXE 97fe565d2160dd4e834f897b77cabf8f Backdoor RBot MSSRV32.EXE 97fe565d2160dd4e834f897b77cabf8f Trojan Agent MSSRV32.EXE 97fe565d2160dd4e834f897b77cabf8f Trojan Small MSSRV32.EXE size: 22016 bytes MSSRV32.EXE hash: 97FE565D2160DD4E834F897B77CABF8F Created files: C:\windows\system32\mssrv32.exe Autostart registry keys: HKLM\System\CurrentControlSet\Services\AFD\Parameters\DisableRawSecurity: 01000000 HKLM\System\CurrentControlSet\Services\msupdate\ImagePath: c:\windows\System32\mssrv32.exe HKLM\System\CurrentControlSet\Services\msupdate\DisplayName: Microsoft security update service HKLM\System\CurrentControlSet\Services\msupdate\Description: This…

Continue reading

SVCHOST.EXE – Trojan Delf

Alex NightWatcher: Solved! Fix it immediately! SVCHOST.EXE – Trojan Delf removal File MD5 Virus Alias SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Delf SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Generic SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Eldorado SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Downloader SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Agent SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Scar SVCHOST.EXE size: 194560 bytes SVCHOST.EXE hash: EA78EB273F0C633B8A0A86F386F2310B Created files: C:\Documents and Settings\LocalService\Local Settings\Application Data\sLT.exf %SysDir%\drivers\svchost.exe Autostart…

Continue reading

SKYPEPLUGIN.EXE – Unknown

Alex NightWatcher: Solved! Fix it immediately! SKYPEPLUGIN.EXE – Unknown removal SKYPEPLUGIN.EXE size: 3676160 bytes SKYPEPLUGIN.EXE hash: 02EB79503179FD11B1144F6E249ACA16 Created files: C:\ProgramData\SkypePlugin.exe Detected by UnHackMe: SKYPEPLUGIN.EXE Default location: C:\PROGRAMDATA\SKYPEPLUGIN.EXE Dropper information: MD5: 5fd2d8141f12e8aebaad55aed1546a46 File size: 3676160 bytes Remove it now! Recommended: UnHackMe anti-rootkit and anti-malware Premium software: RegRun Security Suite (Good choice for removal and protection)