Solved! Use TEST.EXE (Worm Vobfus) Removal Guide

  Manual removal instructions: TEST.EXE – Worm Vobfus removal File MD5 Virus Alias TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Worm Vobfus TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Trojan Generic TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Trojan Hllw TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Backdoor Maximus TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Trojan Agent TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Trojan Crypt TEST.EXE size: 25806 bytes TEST.EXE hash: 8B474678CC1604B6651B97CDCF5B0430 Created files: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\Office Tools.exe C:\TEST.exe %SysDir%\SVCH0ST.EXE D:\TEST.exe…

Continue reading

Solved! Use TEST.EXE (Worm Vobfus) Removal Guide

  Manual removal instructions: TEST.EXE – Worm Vobfus removal File MD5 Virus Alias TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Worm Vobfus TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Trojan Generic TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Trojan Hllw TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Backdoor Maximus TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Trojan Agent TEST.EXE 8b474678cc1604b6651b97cdcf5b0430 Trojan Crypt TEST.EXE size: 25806 bytes TEST.EXE hash: 8B474678CC1604B6651B97CDCF5B0430 Created files: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\Office Tools.exe C:\TEST.exe %SysDir%\SVCH0ST.EXE D:\TEST.exe…

Continue reading

Solved! Use FNRESIIRV.EXE (Trojan FlyStudio) Removal Guide

  Manual removal instructions: FNRESIIRV.EXE – Trojan FlyStudio removal File MD5 Virus Alias FNRESIIRV.EXE d835c0e4b6e1c147699bc6e1673d552e Trojan FlyStudio FNRESIIRV.EXE d835c0e4b6e1c147699bc6e1673d552e Trojan (Suspicious File) FNRESIIRV.EXE d835c0e4b6e1c147699bc6e1673d552e Trojan Downloader FNRESIIRV.EXE d835c0e4b6e1c147699bc6e1673d552e Trojan CI FNRESIIRV.EXE d835c0e4b6e1c147699bc6e1673d552e Worm Autorun FNRESIIRV.EXE d835c0e4b6e1c147699bc6e1673d552e Trojan Agent FNRESIIRV.EXE size: 694296 bytes FNRESIIRV.EXE hash: D835C0E4B6E1C147699BC6E1673D552E Created files: %Program Files%\Fnresiirv.exe %Temp%\E_4\krnln.fnr Detected by UnHackMe: FNRESIIRV.EXE Default…

Continue reading

Solved! Use WINLOGON.EXE (Trojan Delf) Removal Guide

  Manual removal instructions: WINLOGON.EXE – Trojan Delf removal File MD5 Virus Alias WINLOGON.EXE d829ddcd06056add56d6e711c97f6280 Trojan Delf WINLOGON.EXE d829ddcd06056add56d6e711c97f6280 Trojan (Suspicious File) WINLOGON.EXE d829ddcd06056add56d6e711c97f6280 Trojan Artemis WINLOGON.EXE d829ddcd06056add56d6e711c97f6280 Trojan Generic WINLOGON.EXE d829ddcd06056add56d6e711c97f6280 Trojan Agent WINLOGON.EXE d829ddcd06056add56d6e711c97f6280 Trojan Banker WINLOGON.EXE size: 979456 bytes WINLOGON.EXE hash: D829DDCD06056ADD56D6E711C97F6280 Created files: C:\windows\winlogon.exe Detected by UnHackMe: WINLOGON.EXE Default location: %WinDir%\WINLOGON.EXE…

Continue reading

Solved! Use MSHKQ32.EXE (Trojan Agent) Removal Guide

  Manual removal instructions: MSHKQ32.EXE – Trojan Agent removal File MD5 Virus Alias MSHKQ32.EXE c13f07f02429eae9105b206ff00192e4 Trojan Agent MSHKQ32.EXE c13f07f02429eae9105b206ff00192e4 Trojan Small MSHKQ32.EXE size: 572616 bytes MSHKQ32.EXE hash: C13F07F02429EAE9105B206FF00192E4 Created files: %WinDir%\svchost.exe %SysDir%\concp32.exe %SysDir%\explorer.exe %SysDir%\mshkq32.exe %SysDir%\vcl32.exe Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed Components\{E4883584-8B9A-11D5-EBA1-F78EEEEEE983}\StubPath: mshkq32.exe HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VCL: vcl32.exe HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VCL: vcl32.exe Detected by UnHackMe: MSHKQ32.EXE Default location: %SYSDIR%\MSHKQ32.EXE Dropper information:…

Continue reading

Solved! Use FLYBOY.DLL (Trojan OnLineGames) Removal Guide

  Manual removal instructions: FLYBOY.DLL – Trojan OnLineGames removal File MD5 Virus Alias FLYBOY.DLL f8495371cc797419d37e83a6c96031da Trojan OnLineGames FLYBOY.DLL f8495371cc797419d37e83a6c96031da Trojan PcClient FLYBOY.DLL f8495371cc797419d37e83a6c96031da Trojan XPACK FLYBOY.DLL f8495371cc797419d37e83a6c96031da Trojan Generic FLYBOY.DLL f8495371cc797419d37e83a6c96031da Trojan Eldorado FLYBOY.DLL f8495371cc797419d37e83a6c96031da Trojan Downloader FLYBOY.DLL size: 74374 bytes FLYBOY.DLL hash: F8495371CC797419D37E83A6C96031DA Created files: %SysDir%\flyboy.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\999lv\Type: 10000000 HKLM\System\CurrentControlSet\Services\999lv\Start: 02000000 HKLM\System\CurrentControlSet\Services\999lv\ErrorControl:…

Continue reading

Solved! Use KSOKNNBZ.SYS (Unclassified Malware) Removal Guide

  Manual removal instructions: KSOKNNBZ.SYS – Unclassified Malware removal KSOKNNBZ.SYS size: 638976 bytes KSOKNNBZ.SYS hash: 7FC82481EA16E78E40CF01D6155E2134 Created files: %SysDir%\drivers\KsOKnNBZ.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\KsOKnNBZ\Type: 01000000 HKLM\System\CurrentControlSet\Services\KsOKnNBZ\Tag: 01000000 HKLM\System\CurrentControlSet\Services\KsOKnNBZ\ErrorControl: 01000000 HKLM\System\CurrentControlSet\Services\KsOKnNBZ\DisplayName: boiso Driver HKLM\System\CurrentControlSet\Services\KsOKnNBZ\Group: Boot Bus Extender HKLM\System\CurrentControlSet\Services\KsOKnNBZ\ImagePath: System32\DRIVERS\KsOKnNBZ.sys Detected by UnHackMe: KSOKNNBZ.SYS Default location: %SYSDIR%\DRIVERS\KSOKNNBZ.SYS Dropper information: MD5: 1b22a9f63917c82e99584e9e43a6c6ab File size: 1601024 bytes Vote as Harmless(0)Vote…

Continue reading

Solved! Use OHFEET.SYS (Trojan PcClient) Removal Guide

  Manual removal instructions: OHFEET.SYS – Trojan PcClient removal File MD5 Virus Alias OHFEET.SYS 192971a22cbb3af02e7dfa6334d318e5 Trojan PcClient OHFEET.SYS 192971a22cbb3af02e7dfa6334d318e5 Trojan (Suspicious File) OHFEET.SYS 192971a22cbb3af02e7dfa6334d318e5 Trojan Generic OHFEET.SYS 192971a22cbb3af02e7dfa6334d318e5 Trojan Eldorado OHFEET.SYS 192971a22cbb3af02e7dfa6334d318e5 Backdoor PcClien OHFEET.SYS 192971a22cbb3af02e7dfa6334d318e5 Backdoor Hupigon OHFEET.SYS size: 7680 bytes OHFEET.SYS hash: 192971A22CBB3AF02E7DFA6334D318E5 Created files: %SysDir%\drivers\ohfeet.sys %SysDir%\ohfeet.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\vnbnuf\Type: 10010000 HKLM\System\CurrentControlSet\Services\vnbnuf\Start:…

Continue reading

Solved! Use HACKER.COM.CN.EXE (Backdoor Hupigon) Removal Guide

  Manual removal instructions: HACKER.COM.CN.EXE – Backdoor Hupigon removal File MD5 Virus Alias HACKER.COM.CN.EXE bf2d7d56b99f151a5eb1126fbf0a7169 Backdoor Hupigon HACKER.COM.CN.EXE bf2d7d56b99f151a5eb1126fbf0a7169 Trojan (Suspicious File) HACKER.COM.CN.EXE bf2d7d56b99f151a5eb1126fbf0a7169 Trojan Generic HACKER.COM.CN.EXE bf2d7d56b99f151a5eb1126fbf0a7169 Trojan Eldorado HACKER.COM.CN.EXE bf2d7d56b99f151a5eb1126fbf0a7169 Trojan Downloader HACKER.COM.CN.EXE bf2d7d56b99f151a5eb1126fbf0a7169 Trojan Agent HACKER.COM.CN.EXE size: 281600 bytes HACKER.COM.CN.EXE hash: BF2D7D56B99F151A5EB1126FBF0A7169 Created files: %WinDir%\Hacker.com.cn.exe %Temp%\IXP000.TMP\3.exe Autostart registry keys: HKLM\System\CurrentControlSet\Services\GrayPigeon_Hacker.com.cn\Type: 10010000 HKLM\System\CurrentControlSet\Services\GrayPigeon_Hacker.com.cn\Start:…

Continue reading

Solved! Use SETUP50.EXE (Unknown) Removal Guide

  Manual removal instructions: SETUP50.EXE – Unknown removal SETUP50.EXE size: 73216 bytes SETUP50.EXE hash: 8058C01E0B96EC2F74FF764BE1B67D7F Created files: C:\killok\KillOK.exe %Program Files%\Apple Software Update\ijrazyiya.iby %Program Files Common%\Apple\Apple Application Support\brrararqq.jyz %Program Files Common%\Apple\Apple Application Support\bzbyqqjby.jzb %Program Files Common%\Apple\Apple Application Support\defaults.exe %Program Files Common%\Apple\Apple Application Support\distnoted.exe %Program Files Common%\Apple\Apple Application Support\qyajqiaqj.jrr %Program Files Common%\Microsoft Shared\MSInfo\yjayayara.bri %Program Files%\Mozilla Firefox\bzbyqqjby.jzbararqq.jyzayayara.bri %Program…

Continue reading

Solved! Use OHFEET.DLL (Unknown) Removal Guide

  Manual removal instructions: OHFEET.DLL – Unknown removal OHFEET.DLL size: 71236 bytes OHFEET.DLL hash: 38C209E705394870E8EE7C6A21FBFB92 Created files: %SysDir%\drivers\ohfeet.sys %SysDir%\ohfeet.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\vnbnuf\Type: 10010000 HKLM\System\CurrentControlSet\Services\vnbnuf\Start: 02000000 HKLM\System\CurrentControlSet\Services\vnbnuf\ErrorControl: 01000000 HKLM\System\CurrentControlSet\Services\vnbnuf\DisplayName: vnbnuf HKLM\System\CurrentControlSet\Services\vnbnuf\ImagePath: %WinDir%\System32\svchost.exe -k vnbnuf HKLM\System\CurrentControlSet\Services\vnbnuf\Description: Microsoft .NET Framework TPM HKLM\System\CurrentControlSet\Services\vnbnuf\Parameters\ServiceDll: 2500530079007300740065006D0052006F006F00740025005C00530079007300740065006D00330032005C006F00680066006500650074002E0064006C006C000000 HKLM\System\CurrentControlSet\Services\ynbnufhc\Type: 01000000 HKLM\System\CurrentControlSet\Services\ynbnufhc\Start: 02000000 HKLM\System\CurrentControlSet\Services\ynbnufhc\ErrorControl: 01000000 HKLM\System\CurrentControlSet\Services\ynbnufhc\DisplayName: ynbnufhc HKLM\System\CurrentControlSet\Services\ynbnufhc\ImagePath: %WinDir%\System32\drivers\ohfeet.sys Detected by UnHackMe: OHFEET.DLL…

Continue reading

Solved! Use DISTNOTED.EXE (Unknown) Removal Guide

  Manual removal instructions: DISTNOTED.EXE – Unknown removal DISTNOTED.EXE size: 13672 bytes DISTNOTED.EXE hash: 7539D96A5AE8A59DAB8C024A7F820514 Created files: C:\killok\KillOK.exe %Program Files%\Apple Software Update\ijrazyiya.iby %Program Files Common%\Apple\Apple Application Support\brrararqq.jyz %Program Files Common%\Apple\Apple Application Support\bzbyqqjby.jzb %Program Files Common%\Apple\Apple Application Support\defaults.exe %Program Files Common%\Apple\Apple Application Support\distnoted.exe %Program Files Common%\Apple\Apple Application Support\qyajqiaqj.jrr %Program Files Common%\Microsoft Shared\MSInfo\yjayayara.bri %Program Files%\Mozilla Firefox\bzbyqqjby.jzbararqq.jyzayayara.bri %Program…

Continue reading

Solved! Use USR_SHOHDI_PHOTO_USR.RSU (Worm Viking) Removal Guide

  Manual removal instructions: USR_SHOHDI_PHOTO_USR.RSU – Worm Viking removal File MD5 Virus Alias USR_SHOHDI_PHOTO_USR.RSU 7afbb50af5ce19db44b6295a6e083fa1 Worm Viking USR_SHOHDI_PHOTO_USR.RSU 7afbb50af5ce19db44b6295a6e083fa1 Trojan Agent USR_SHOHDI_PHOTO_USR.RSU 7afbb50af5ce19db44b6295a6e083fa1 Trojan Small USR_SHOHDI_PHOTO_USR.RSU size: 344092 bytes USR_SHOHDI_PHOTO_USR.RSU hash: 7AFBB50AF5CE19DB44B6295A6E083FA1 Created files: %SysDir%\USR_Shohdi_Photo_USR.rsu %WinDir%\USR_Shohdi_Photo_USR.exe %Common AppData%\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.usr Detected by UnHackMe: USR_SHOHDI_PHOTO_USR.RSU Default location: %SYSDIR%\USR_SHOHDI_PHOTO_USR.RSU Dropper information: MD5: d6794f84f0bf10f703ecb52cf15ee577 File size: 344092…

Continue reading

Solved! Use STARTER.EXE (Trojan Genome) Removal Guide

  Manual removal instructions: STARTER.EXE – Trojan Genome removal File MD5 Virus Alias STARTER.EXE 40ebe5d9d4ecf71c857c3f4c8d0f7395 Trojan Genome STARTER.EXE 40ebe5d9d4ecf71c857c3f4c8d0f7395 Trojan PAK_Generic STARTER.EXE 40ebe5d9d4ecf71c857c3f4c8d0f7395 Trojan Win32-Spy STARTER.EXE 40ebe5d9d4ecf71c857c3f4c8d0f7395 Trojan, Suspicious File STARTER.EXE 40ebe5d9d4ecf71c857c3f4c8d0f7395 Trojan Artemis STARTER.EXE 40ebe5d9d4ecf71c857c3f4c8d0f7395 Trojan Generic STARTER.EXE size: 46080 bytes STARTER.EXE hash: 40EBE5D9D4ECF71C857C3F4C8D0F7395 Created files: C:\a8wincs\Klijent.exe C:\a8wincs\LivePlayer.exe C:\a8wincs\LSPlayer.exe C:\a8wincs\msvcr100.dll C:\a8wincs\Starter.exe C:\a8wincs\TPPlayer.exe C:\a8wincs\voice\speex.dll Detected…

Continue reading

Solved! Use LIVEPLAYER.EXE (Trojan, Suspicious File) Removal Guide

  Manual removal instructions: LIVEPLAYER.EXE – Trojan, Suspicious File removal File MD5 Virus Alias LIVEPLAYER.EXE 47ca3fe374b21230776b00dae20cf71e Trojan, Suspicious File LIVEPLAYER.EXE 47ca3fe374b21230776b00dae20cf71e Trojan Downloader LIVEPLAYER.EXE size: 1090560 bytes LIVEPLAYER.EXE hash: 47CA3FE374B21230776B00DAE20CF71E Created files: C:\a8wincs\Klijent.exe C:\a8wincs\LivePlayer.exe C:\a8wincs\LSPlayer.exe C:\a8wincs\msvcr100.dll C:\a8wincs\Starter.exe C:\a8wincs\TPPlayer.exe C:\a8wincs\voice\speex.dll Detected by UnHackMe: LIVEPLAYER.EXE Default location: C:\A8WINCS\LIVEPLAYER.EXE Dropper information: MD5: 685805b2d4dc8fedc5296acb5bc35f46 File size: 8588823 bytes Vote…

Continue reading

Solved! Use LSPLAYER.EXE (Unclassified Malware) Removal Guide

  Manual removal instructions: LSPLAYER.EXE – Unclassified Malware removal LSPLAYER.EXE size: 4922368 bytes LSPLAYER.EXE hash: 7C269D184E2BB38780F22C23FF065D6B Created files: C:\a8wincs\Klijent.exe C:\a8wincs\LivePlayer.exe C:\a8wincs\LSPlayer.exe C:\a8wincs\msvcr100.dll C:\a8wincs\Starter.exe C:\a8wincs\TPPlayer.exe C:\a8wincs\voice\speex.dll Detected by UnHackMe: LSPLAYER.EXE Default location: C:\A8WINCS\LSPLAYER.EXE Dropper information: MD5: 685805b2d4dc8fedc5296acb5bc35f46 File size: 8588823 bytes Vote as Harmless(0)Vote as Malicious(0)Remove it now! Recommended: UnHackMe anti-rootkit and anti-malware Premium software: RegRun…

Continue reading

Solved! Use STARPLAYERMG.EXE (Trojan Downloader) Removal Guide

  Manual removal instructions: STARPLAYERMG.EXE – Trojan Downloader removal File MD5 Virus Alias STARPLAYERMG.EXE e93bde7dd85ad38599e091c9ec44ea01 Trojan Downloader STARPLAYERMG.EXE size: 819264 bytes STARPLAYERMG.EXE hash: E93BDE7DD85AD38599E091C9EC44EA01 Created files: %Program Files%\Axissoft\StarPlayerAgent\LICENSE %Program Files%\Axissoft\StarPlayerAgent\StarPlayer.exe %Program Files%\Axissoft\StarPlayerAgent\StarPlayerMG.exe %Program Files%\Axissoft\StarPlayerAgent\uninstall.exe %Common AppData%\Microsoft\Dr Watson\user.dmp %Temp%\142E69.dmp Autostart registry keys: HKLM\System\CurrentControlSet\Services\StarPlayer\Type: 10010000 HKLM\System\CurrentControlSet\Services\StarPlayer\Start: 02000000 HKLM\System\CurrentControlSet\Services\StarPlayer\DisplayName: StarPlayer HKLM\System\CurrentControlSet\Services\StarPlayer\ImagePath: %Program Files%\Axissoft\StarPlayerAgent\StarPlayer.exe Detected by UnHackMe: STARPLAYERMG.EXE Default…

Continue reading

Solved! Use NWCWKS.DLL (Trojan Graftor) Removal Guide

  Manual removal instructions: NWCWKS.DLL – Trojan Graftor removal File MD5 Virus Alias NWCWKS.DLL 560f8147e9bb5a728d8715120d2f7e7f Trojan Graftor NWCWKS.DLL 560f8147e9bb5a728d8715120d2f7e7f Trojan (Suspicious File) NWCWKS.DLL 560f8147e9bb5a728d8715120d2f7e7f Trojan Generic NWCWKS.DLL 560f8147e9bb5a728d8715120d2f7e7f Trojan Vilsel NWCWKS.DLL 560f8147e9bb5a728d8715120d2f7e7f Trojan Agent NWCWKS.DLL 560f8147e9bb5a728d8715120d2f7e7f Trojan Crypt NWCWKS.DLL size: 8192 bytes NWCWKS.DLL hash: 560F8147E9BB5A728D8715120D2F7E7F Created files: %SysDir%\nwcwks.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\6to4\SBIE_Win32ExitCode: 02000000 HKLM\System\CurrentControlSet\Services\NWCWorkstation\Type: 20000000…

Continue reading

Solved! Use NOTICE.EXE (Unclassified Malware) Removal Guide

  Manual removal instructions: NOTICE.EXE – Unclassified Malware removal NOTICE.EXE size: 24576 bytes NOTICE.EXE hash: 8FED9734E347E853A8DCBDBD5FBE610D Created files: %WinDir%\system\sundy\clienter\update\clientcom.dll %WinDir%\system\sundy\clienter\update\clienter.exe %WinDir%\system\sundy\clienter\update\monitorclient.exe %WinDir%\system\sundy\clienter\update\notice.exe %WinDir%\system\sundy\clienter\update\upgrade.exe Detected by UnHackMe: NOTICE.EXE Default location: %WinDir%\SYSTEM\SUNDY\CLIENTER\UPDATE\NOTICE.EXE Dropper information: MD5: d7247c7f04c852f6cf7e945a9063e0e0 File size: 797810 bytes Vote as Harmless(0)Vote as Malicious(0)Remove it now! Recommended: UnHackMe anti-rootkit and anti-malware Premium software: RegRun Security Suite…

Continue reading

Solved! Use MIRAA .EXE (Trojan Agent) Removal Guide

  Manual removal instructions: MIRAA .EXE – Trojan Agent removal File MD5 Virus Alias MIRAA .EXE ed03b1b4384f5a74fc2a14624f0653de Trojan Agent MIRAA .EXE ed03b1b4384f5a74fc2a14624f0653de Trojan ZBot MIRAA .EXE size: 512382 bytes MIRAA .EXE hash: ED03B1B4384F5A74FC2A14624F0653DE Created files: C:\. .exe C:\.. .exe C:\AUTOEXEC.BAT .exe C:\boot.ini .exe C:\CONFIG.SYS C:\CONFIG.SYS .exe C:\Documents and Settings .exe C:\IO.SYS C:\IO.SYS .exe C:\killok .exe…

Continue reading

Solved! Use DPRSRV32.EXE (Trojan Artemis) Removal Guide

  Manual removal instructions: DPRSRV32.EXE – Trojan Artemis removal File MD5 Virus Alias DPRSRV32.EXE d7401c95ee79fcbef6966bb3567dac40 Trojan Artemis DPRSRV32.EXE d7401c95ee79fcbef6966bb3567dac40 Trojan (Suspicious File) DPRSRV32.EXE d7401c95ee79fcbef6966bb3567dac40 Trojan XPACK DPRSRV32.EXE d7401c95ee79fcbef6966bb3567dac40 Trojan Generic DPRSRV32.EXE d7401c95ee79fcbef6966bb3567dac40 Trojan BZub DPRSRV32.EXE d7401c95ee79fcbef6966bb3567dac40 Trojan DNAScan DPRSRV32.EXE size: 98304 bytes DPRSRV32.EXE hash: D7401C95EE79FCBEF6966BB3567DAC40 Created files: %SysDir%\dprsrv32.exe Detected by UnHackMe: DPRSRV32.EXE Default location: %SYSDIR%\DPRSRV32.EXE…

Continue reading

Solved! Use MIRAT .EXE (Trojan Agent) Removal Guide

  Manual removal instructions: MIRAT .EXE – Trojan Agent removal File MD5 Virus Alias MIRAT .EXE ba0685b845d6e6621a6059afffe0680c Trojan Agent MIRAT .EXE ba0685b845d6e6621a6059afffe0680c Trojan ZBot MIRAT .EXE size: 488876 bytes MIRAT .EXE hash: BA0685B845D6E6621A6059AFFFE0680C Created files: C:\. .exe C:\.. .exe C:\AUTOEXEC.BAT .exe C:\boot.ini .exe C:\CONFIG.SYS C:\CONFIG.SYS .exe C:\Documents and Settings .exe C:\IO.SYS C:\IO.SYS .exe C:\killok .exe…

Continue reading

Solved! Use UNINS000.EXE (Adware – Unwanted Program) Removal Guide

  Manual removal instructions: UNINS000.EXE – Adware – Unwanted Program removal File MD5 Virus Alias UNINS000.EXE 00f35bd31ce5a5e47e59767b17b207b5 Adware – Unwanted Program UNINS000.EXE 00f35bd31ce5a5e47e59767b17b207b5 Trojan Downloader UNINS000.EXE size: 1554592 bytes UNINS000.EXE hash: 00F35BD31CE5A5E47E59767B17B207B5 Created files: %Program Files%\Super Updater\7z.dll %Program Files%\Super Updater\SuperUpdater.exe %Program Files%\Super Updater\SupUpdHelper.dll %Program Files%\Super Updater\SUStartScan.exe %Program Files%\Super Updater\SUTray.exe %Program Files%\Super Updater\unins000.exe %Temp%\is-VQGS2.tmp\SupUpdHelper.dll %Temp%\supupdsetup.exe Detected…

Continue reading

Solved! Use SVCHSOT.EXE (Backdoor Zegost) Removal Guide

  Manual removal instructions: SVCHSOT.EXE – Backdoor Zegost removal File MD5 Virus Alias SVCHSOT.EXE ed5fbb83f1f6b247a2fbcc6111e6b9ed Backdoor Zegost SVCHSOT.EXE ed5fbb83f1f6b247a2fbcc6111e6b9ed Trojan Win32-Spy SVCHSOT.EXE ed5fbb83f1f6b247a2fbcc6111e6b9ed Trojan XPACK SVCHSOT.EXE ed5fbb83f1f6b247a2fbcc6111e6b9ed Trojan Generic SVCHSOT.EXE ed5fbb83f1f6b247a2fbcc6111e6b9ed Trojan CI SVCHSOT.EXE ed5fbb83f1f6b247a2fbcc6111e6b9ed Trojan Agent SVCHSOT.EXE size: 210944 bytes SVCHSOT.EXE hash: ED5FBB83F1F6B247A2FBCC6111E6B9ED Created files: %WinDir%\XXXXXXCA861122\svchsot.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\XXXXXXCA861122: %WinDir%\XXXXXXCA861122\svchsot.exe Detected by UnHackMe:…

Continue reading

Solved! Use 45EZSETP.DLL (Adware MyWebSearch) Removal Guide

  Manual removal instructions: 45EZSETP.DLL – Adware MyWebSearch removal File MD5 Virus Alias 45EZSETP.DLL bd51f9e4f5784ff45336219d39297ff4 Adware MyWebSearch 45EZSETP.DLL bd51f9e4f5784ff45336219d39297ff4 Adware – Unwanted Program 45EZSETP.DLL bd51f9e4f5784ff45336219d39297ff4 Adware FunWeb 45EZSETP.DLL size: 219176 bytes 45EZSETP.DLL hash: BD51F9E4F5784FF45336219D39297FF4 Created files: %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EIPlug.dll %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EIPlug.dl_ %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EZSETP.dll %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EZSETP.dl_ %Program Files%\QuotationCafe_45EI\Installr\1.bin\NP45EISb.dll %Program Files%\QuotationCafe_45EI\Installr\1.bin\NP45EISb.dl_ Detected by UnHackMe: 45EZSETP.DLL Default location: %PROGRAM…

Continue reading

Solved! Use NP45EISB.DLL (Adware MyWebSearch) Removal Guide

  Manual removal instructions: NP45EISB.DLL – Adware MyWebSearch removal File MD5 Virus Alias NP45EISB.DLL d7ecd0f41cc81961d83c5c816c771282 Adware MyWebSearch NP45EISB.DLL d7ecd0f41cc81961d83c5c816c771282 Adware – Unwanted Program NP45EISB.DLL d7ecd0f41cc81961d83c5c816c771282 Adware Downware NP45EISB.DLL size: 30768 bytes NP45EISB.DLL hash: D7ECD0F41CC81961D83C5C816C771282 Created files: %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EIPlug.dll %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EIPlug.dl_ %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EZSETP.dll %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EZSETP.dl_ %Program Files%\QuotationCafe_45EI\Installr\1.bin\NP45EISb.dll %Program Files%\QuotationCafe_45EI\Installr\1.bin\NP45EISb.dl_ Detected by UnHackMe: NP45EISB.DLL Default location: %PROGRAM…

Continue reading

Solved! Use 45EIPLUG.DLL (Adware MyWebSearch) Removal Guide

  Manual removal instructions: 45EIPLUG.DLL – Adware MyWebSearch removal File MD5 Virus Alias 45EIPLUG.DLL f1408f4e4ba0538d4f6a81c54be70881 Adware MyWebSearch 45EIPLUG.DLL size: 55336 bytes 45EIPLUG.DLL hash: F1408F4E4BA0538D4F6A81C54BE70881 Created files: %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EIPlug.dll %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EIPlug.dl_ %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EZSETP.dll %Program Files%\QuotationCafe_45EI\Installr\1.bin\45EZSETP.dl_ %Program Files%\QuotationCafe_45EI\Installr\1.bin\NP45EISb.dll %Program Files%\QuotationCafe_45EI\Installr\1.bin\NP45EISb.dl_ Detected by UnHackMe: 45EIPLUG.DLL Default location: %PROGRAM FILES%\QUOTATIONCAFE_45EI\INSTALLR\1.BIN\45EIPLUG.DLL Dropper information: MD5: 6c8b67f570aac7043e347033a47b9892 File size: 210992 bytes Vote…

Continue reading

Solved! Use WLLAMEK.EXE (Trojan OnLineGames) Removal Guide

  Manual removal instructions: WLLAMEK.EXE – Trojan OnLineGames removal File MD5 Virus Alias WLLAMEK.EXE d73933e3c56dc3b6878464dea67094e0 Trojan OnLineGames WLLAMEK.EXE d73933e3c56dc3b6878464dea67094e0 Trojan Eldorado WLLAMEK.EXE d73933e3c56dc3b6878464dea67094e0 Trojan Agent WLLAMEK.EXE d73933e3c56dc3b6878464dea67094e0 Trojan ZBot WLLAMEK.EXE size: 14337 bytes WLLAMEK.EXE hash: D73933E3C56DC3B6878464DEA67094E0 Created files: %SysDir%\wllame.dll %SysDir%\wllamek.exe Detected by UnHackMe: WLLAMEK.EXE Default location: %SYSDIR%\WLLAMEK.EXE Dropper information: MD5: d73933e3c56dc3b6878464dea67094e0 File size: 14337 bytes…

Continue reading

Solved! Use RIERCUX.EXE (Trojan Urelas) Removal Guide

  Manual removal instructions: RIERCUX.EXE – Trojan Urelas removal File MD5 Virus Alias RIERCUX.EXE e37c1b8752cfa5d0ed820c2f92c3be79 Trojan Urelas RIERCUX.EXE e37c1b8752cfa5d0ed820c2f92c3be79 Trojan XPACK RIERCUX.EXE e37c1b8752cfa5d0ed820c2f92c3be79 Trojan Eldorado RIERCUX.EXE e37c1b8752cfa5d0ed820c2f92c3be79 Trojan Agent RIERCUX.EXE e37c1b8752cfa5d0ed820c2f92c3be79 Trojan AVKill RIERCUX.EXE e37c1b8752cfa5d0ed820c2f92c3be79 Virus Sality RIERCUX.EXE size: 680872 bytes RIERCUX.EXE hash: E37C1B8752CFA5D0ED820C2F92C3BE79 Created files: %SysDir%\riercux.exe Detected by UnHackMe: RIERCUX.EXE Default location: %SYSDIR%\RIERCUX.EXE Dropper…

Continue reading

Solved! Use WLLAME.DLL (Trojan OnLineGames) Removal Guide

  Manual removal instructions: WLLAME.DLL – Trojan OnLineGames removal File MD5 Virus Alias WLLAME.DLL 4cb226f638e2961100fcf31aa1ed7daf Trojan OnLineGames WLLAME.DLL 4cb226f638e2961100fcf31aa1ed7daf Trojan Generic WLLAME.DLL 4cb226f638e2961100fcf31aa1ed7daf Trojan Eldorado WLLAME.DLL 4cb226f638e2961100fcf31aa1ed7daf Trojan Magania WLLAME.DLL 4cb226f638e2961100fcf31aa1ed7daf Trojan Agent WLLAME.DLL size: 28672 bytes WLLAME.DLL hash: 4CB226F638E2961100FCF31AA1ED7DAF Created files: %SysDir%\wllame.dll %SysDir%\wllamek.exe Detected by UnHackMe: WLLAME.DLL Default location: %SYSDIR%\WLLAME.DLL Dropper information: MD5: d73933e3c56dc3b6878464dea67094e0…

Continue reading

Solved! Use C_813.NLS (Virus Alman) Removal Guide

  Manual removal instructions: C_813.NLS – Virus Alman removal File MD5 Virus Alias C_813.NLS 7b62e67d68567d298d9e8df44d4af7a6 Virus Alman C_813.NLS 7b62e67d68567d298d9e8df44d4af7a6 Trojan Generic C_813.NLS 7b62e67d68567d298d9e8df44d4af7a6 Trojan Click C_813.NLS 7b62e67d68567d298d9e8df44d4af7a6 Trojan Downloader C_813.NLS 7b62e67d68567d298d9e8df44d4af7a6 Trojan Agent C_813.NLS size: 25088 bytes C_813.NLS hash: 7B62E67D68567D298D9E8DF44D4AF7A6 Created files: %WinDir%\AppPatch\deamon.dll %WinDir%\c_813.nls Detected by UnHackMe: C_813.NLS Default location: %WinDir%\C_813.NLS Dropper information: MD5: d74675a92e3ea8716186aa13518f1220…

Continue reading

Solved! Use YHESXUK.EXE (Trojan Urelas) Removal Guide

  Manual removal instructions: YHESXUK.EXE – Trojan Urelas removal File MD5 Virus Alias YHESXUK.EXE 1fb3a2a42c5f5b6a710a0ca12ad6f492 Trojan Urelas YHESXUK.EXE 1fb3a2a42c5f5b6a710a0ca12ad6f492 Trojan XPACK YHESXUK.EXE 1fb3a2a42c5f5b6a710a0ca12ad6f492 Trojan Eldorado YHESXUK.EXE 1fb3a2a42c5f5b6a710a0ca12ad6f492 Trojan Agent YHESXUK.EXE 1fb3a2a42c5f5b6a710a0ca12ad6f492 Trojan AVKill YHESXUK.EXE 1fb3a2a42c5f5b6a710a0ca12ad6f492 Virus Sality YHESXUK.EXE size: 619181 bytes YHESXUK.EXE hash: 1FB3A2A42C5F5B6A710A0CA12AD6F492 Created files: %SysDir%\yhesxuk.exe Detected by UnHackMe: YHESXUK.EXE Default location: %SYSDIR%\YHESXUK.EXE Dropper…

Continue reading

Solved! Use SVCHOSTS.EXE (Trojan Banker) Removal Guide

  Manual removal instructions: SVCHOSTS.EXE – Trojan Banker removal File MD5 Virus Alias SVCHOSTS.EXE d70698aa3f54360ae823b0105802646e Trojan Banker SVCHOSTS.EXE d70698aa3f54360ae823b0105802646e Trojan (Suspicious File) SVCHOSTS.EXE d70698aa3f54360ae823b0105802646e Trojan Eldorado SVCHOSTS.EXE d70698aa3f54360ae823b0105802646e Trojan Bancos SVCHOSTS.EXE d70698aa3f54360ae823b0105802646e Trojan Agent SVCHOSTS.EXE d70698aa3f54360ae823b0105802646e Trojan Delf SVCHOSTS.EXE size: 685568 bytes SVCHOSTS.EXE hash: D70698AA3F54360AE823B0105802646E Created files: %WinDir%\svchosts.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\svchosts: %WinDir%\svchosts.exe Detected by…

Continue reading

Solved! Use WININIT32.EXE (Backdoor IRCBot) Removal Guide

  Manual removal instructions: WININIT32.EXE – Backdoor IRCBot removal File MD5 Virus Alias WININIT32.EXE 8077cf0af4592f4c2cc5abbbfa6fcf83 Backdoor IRCBot WININIT32.EXE 8077cf0af4592f4c2cc5abbbfa6fcf83 Trojan (Suspicious File) WININIT32.EXE 8077cf0af4592f4c2cc5abbbfa6fcf83 Trojan DNAScan WININIT32.EXE 8077cf0af4592f4c2cc5abbbfa6fcf83 Virus Part WININIT32.EXE 8077cf0af4592f4c2cc5abbbfa6fcf83 Worm Palevo WININIT32.EXE 8077cf0af4592f4c2cc5abbbfa6fcf83 Backdoor Maximus WININIT32.EXE size: 520920 bytes WININIT32.EXE hash: 8077CF0AF4592F4C2CC5ABBBFA6FCF83 Created files: %SysDir%\wininit32.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SysInit: wininit32.exe -services HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\SysInit:…

Continue reading

Solved! Use IQGM79W.DLL (Rootkit TDSS) Removal Guide

  Manual removal instructions: IQGM79W.DLL – Rootkit TDSS removal File MD5 Virus Alias IQGM79W.DLL 73633b26a0e19ad438879b4d086280b4 Rootkit TDSS IQGM79W.DLL 73633b26a0e19ad438879b4d086280b4 Trojan Ransom IQGM79W.DLL 73633b26a0e19ad438879b4d086280b4 Trojan Eldorado IQGM79W.DLL 73633b26a0e19ad438879b4d086280b4 Trojan Kazy IQGM79W.DLL 73633b26a0e19ad438879b4d086280b4 Trojan DNSChanger IQGM79W.DLL 73633b26a0e19ad438879b4d086280b4 Trojan Vundo IQGM79W.DLL size: 118272 bytes IQGM79W.DLL hash: 73633B26A0E19AD438879B4D086280B4 Created files: %WinDir%\System32\spool\PRTPROCS\W32X86\iQGM79w.dll %Temp%\3o79m1gM Detected by UnHackMe: IQGM79W.DLL Default location: %SYSDIR%\SPOOL\PRTPROCS\W32X86\IQGM79W.DLL…

Continue reading

Solved! Use SERVER.EXE (Trojan Delf) Removal Guide

  Manual removal instructions: SERVER.EXE – Trojan Delf removal File MD5 Virus Alias SERVER.EXE d84960d5dffcb07bfbc1e63187b2d6b0 Trojan Delf SERVER.EXE d84960d5dffcb07bfbc1e63187b2d6b0 Trojan (Suspicious File) SERVER.EXE d84960d5dffcb07bfbc1e63187b2d6b0 Trojan Artemis SERVER.EXE d84960d5dffcb07bfbc1e63187b2d6b0 Backdoor Cybergate SERVER.EXE d84960d5dffcb07bfbc1e63187b2d6b0 Trojan Downloader SERVER.EXE d84960d5dffcb07bfbc1e63187b2d6b0 Backdoor Poison SERVER.EXE size: 483840 bytes SERVER.EXE hash: D84960D5DFFCB07BFBC1E63187B2D6B0 Created files: C:\dir\install\install\server.exe %Temp%\UuU.uUu %Temp%\XxX.xXx Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed…

Continue reading

Solved! Use MSIMN.EXE.EXE (Worm Autorun) Removal Guide

  Manual removal instructions: MSIMN.EXE.EXE – Worm Autorun removal File MD5 Virus Alias MSIMN.EXE.EXE 47c75762708f33abe53ee0720ffe0555 Worm Autorun MSIMN.EXE.EXE 47c75762708f33abe53ee0720ffe0555 Trojan Generic MSIMN.EXE.EXE 47c75762708f33abe53ee0720ffe0555 Trojan Agent MSIMN.EXE.EXE 47c75762708f33abe53ee0720ffe0555 Trojan Delf MSIMN.EXE.EXE size: 268336 bytes MSIMN.EXE.EXE hash: 47C75762708F33ABE53EE0720FFE0555 Created files: %Program Files%\Internet Explorer\iexplore.exe.exe %Program Files%\Outlook Express\msimn.exe.exe %SysDir%\HelpMe.exe %SysDir%\notepad.exe.exe %Temp%\MZ? Autostart registry keys: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe HelpMe.exe Detected…

Continue reading

Solved! Use IEXPLORE.EXE.EXE (Worm Autorun) Removal Guide

  Manual removal instructions: IEXPLORE.EXE.EXE – Worm Autorun removal File MD5 Virus Alias IEXPLORE.EXE.EXE 93cd65b4b05c111982d5855ea3c1ee8b Worm Autorun IEXPLORE.EXE.EXE 93cd65b4b05c111982d5855ea3c1ee8b Trojan Generic IEXPLORE.EXE.EXE 93cd65b4b05c111982d5855ea3c1ee8b Trojan Agent IEXPLORE.EXE.EXE 93cd65b4b05c111982d5855ea3c1ee8b Trojan Delf IEXPLORE.EXE.EXE size: 846736 bytes IEXPLORE.EXE.EXE hash: 93CD65B4B05C111982D5855EA3C1EE8B Created files: %Program Files%\Internet Explorer\iexplore.exe.exe %Program Files%\Outlook Express\msimn.exe.exe %SysDir%\HelpMe.exe %SysDir%\notepad.exe.exe %Temp%\MZ? Autostart registry keys: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe HelpMe.exe Detected…

Continue reading

Solved! Use MSQGW32.EXE (Trojan Agent) Removal Guide

  Manual removal instructions: MSQGW32.EXE – Trojan Agent removal File MD5 Virus Alias MSQGW32.EXE f3df289f50d7111ab5ae5c2a7ef104b6 Trojan Agent MSQGW32.EXE f3df289f50d7111ab5ae5c2a7ef104b6 Trojan Small MSQGW32.EXE size: 681101 bytes MSQGW32.EXE hash: F3DF289F50D7111AB5AE5C2A7EF104B6 Created files: %WinDir%\spoolsv.exe %SysDir%\concp32.exe %SysDir%\explorer.exe %SysDir%\msqgw32.exe %SysDir%\vcl32.exe Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed Components\{E4883584-8B9A-11D5-EBA1-F78EEEEEE983}\StubPath: msqgw32.exe HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VCL: vcl32.exe HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VCL: vcl32.exe Detected by UnHackMe: MSQGW32.EXE Default location: %SYSDIR%\MSQGW32.EXE Dropper information:…

Continue reading

Solved! Use CODECSWIN.EXE (Trojan Bancos) Removal Guide

  Manual removal instructions: CODECSWIN.EXE – Trojan Bancos removal File MD5 Virus Alias CODECSWIN.EXE d84879cf24508ca0d0283d64a37e47ce Trojan Bancos CODECSWIN.EXE d84879cf24508ca0d0283d64a37e47ce Trojan (Suspicious File) CODECSWIN.EXE d84879cf24508ca0d0283d64a37e47ce Trojan Generic CODECSWIN.EXE d84879cf24508ca0d0283d64a37e47ce Trojan Banker CODECSWIN.EXE d84879cf24508ca0d0283d64a37e47ce Trojan Crypt CODECSWIN.EXE size: 143360 bytes CODECSWIN.EXE hash: D84879CF24508CA0D0283D64A37E47CE Created files: C:\windows\codecswin.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Corporation NT: “C:\windows\CodecsWin.exe” Detected by UnHackMe: CODECSWIN.EXE…

Continue reading

Solved! Use LSASS.EXE (Worm Autoit) Removal Guide

  Manual removal instructions: LSASS.EXE – Worm Autoit removal File MD5 Virus Alias LSASS.EXE d82561b725104a54fb558f44dfd50a5f Worm Autoit LSASS.EXE d82561b725104a54fb558f44dfd50a5f Trojan Hllw LSASS.EXE d82561b725104a54fb558f44dfd50a5f Trojan Downloader LSASS.EXE d82561b725104a54fb558f44dfd50a5f Worm Autorun LSASS.EXE d82561b725104a54fb558f44dfd50a5f Trojan Agent LSASS.EXE size: 366592 bytes LSASS.EXE hash: D82561B725104A54FB558F44DFD50A5F Created files: C:\Win\lsass.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\run32: C:\Win\lsass.exe Detected by UnHackMe: LSASS.EXE Default location: C:\WIN\LSASS.EXE…

Continue reading

Solved! Use HOIFNW.SYS (Backdoor Koutodoor) Removal Guide

  Manual removal instructions: HOIFNW.SYS – Backdoor Koutodoor removal File MD5 Virus Alias HOIFNW.SYS 63e1abfc2155ba0e2bab12f684ea9a41 Backdoor Koutodoor HOIFNW.SYS 63e1abfc2155ba0e2bab12f684ea9a41 Trojan Generic HOIFNW.SYS 63e1abfc2155ba0e2bab12f684ea9a41 Trojan Eldorado HOIFNW.SYS 63e1abfc2155ba0e2bab12f684ea9a41 Trojan Siggen HOIFNW.SYS 63e1abfc2155ba0e2bab12f684ea9a41 Trojan Agent HOIFNW.SYS 63e1abfc2155ba0e2bab12f684ea9a41 Trojan Crypt HOIFNW.SYS size: 38304 bytes HOIFNW.SYS hash: 63E1ABFC2155BA0E2BAB12F684EA9A41 Created files: %SysDir%\drivers\hoifnw.sys %SysDir%\qof.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\hoifnw\Type: 01000000 HKLM\System\CurrentControlSet\Services\hoifnw\ErrorControl: 01000000…

Continue reading

Solved! Use VD2.EXE (Virus Madang) Removal Guide

  Manual removal instructions: VD2.EXE – Virus Madang removal File MD5 Virus Alias VD2.EXE eb31c19802fc0519e5f7438f202618ad Virus Madang VD2.EXE eb31c19802fc0519e5f7438f202618ad Trojan XPACK VD2.EXE eb31c19802fc0519e5f7438f202618ad Trojan Generic VD2.EXE size: 10240 bytes VD2.EXE hash: EB31C19802FC0519E5F7438F202618AD Created files: %Program Files%\Mozilla Firefox\firefox.xzg %Program Files%\MSN Gaming Zone\Windows\bckgzm.exe %Program Files%\MSN Gaming Zone\Windows\chkrzm.exe %Program Files%\NetMeeting\conf.bew %Program Files%\Vd2.exe %Program Files%\Windows NT\dialer.ogm %SysDir%\taskmgr.exe %SysDir%\VBoxService.exe %SysDir%\Winkber.exe…

Continue reading

Solved! Use QOF.DLL (Backdoor Koutodoor) Removal Guide

  Manual removal instructions: QOF.DLL – Backdoor Koutodoor removal File MD5 Virus Alias QOF.DLL d0a6f64d0e96e587e1f8f3a98f990866 Backdoor Koutodoor QOF.DLL d0a6f64d0e96e587e1f8f3a98f990866 Trojan Generic QOF.DLL d0a6f64d0e96e587e1f8f3a98f990866 Trojan Eldorado QOF.DLL d0a6f64d0e96e587e1f8f3a98f990866 Trojan Adload QOF.DLL d0a6f64d0e96e587e1f8f3a98f990866 Trojan Agent QOF.DLL size: 53248 bytes QOF.DLL hash: D0A6F64D0E96E587E1F8F3A98F990866 Created files: %SysDir%\drivers\hoifnw.sys %SysDir%\qof.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\hoifnw\Type: 01000000 HKLM\System\CurrentControlSet\Services\hoifnw\ErrorControl: 01000000 HKLM\System\CurrentControlSet\Services\hoifnw\DisplayName: hoifnw HKLM\System\CurrentControlSet\Services\hoifnw\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C0068006F00690066006E0077002E007300790073000000…

Continue reading

Solved! Use ZNF6.EXE (Trojan Hllw) Removal Guide

  Manual removal instructions: ZNF6.EXE – Trojan Hllw removal File MD5 Virus Alias ZNF6.EXE 97e6df35d9b2b260065231329ae618b6 Trojan Hllw ZNF6.EXE size: 1032192 bytes ZNF6.EXE hash: 97E6DF35D9B2B260065231329AE618B6 Created files: %Program Files%\Mozilla Firefox\firefox.xzg %Program Files%\MSN Gaming Zone\Windows\bckgzm.exe %Program Files%\MSN Gaming Zone\Windows\chkrzm.exe %Program Files%\NetMeeting\conf.bew %Program Files%\Vd2.exe %Program Files%\Windows NT\dialer.ogm %SysDir%\taskmgr.exe %SysDir%\VBoxService.exe %SysDir%\Winkber.exe %TEMP%\Aph7.exe %TEMP%\Cis3.exe %TEMP%\Fcg5.exe %TEMP%\Jnm4.exe %TEMP%\Qzm9.exe %TEMP%\Znf6.exe %TEMP%\Ztr8.exe \\VBOXSVR\in\Mdx.txt.exe…

Continue reading

Solved! Use MSHAS32.EXE (Trojan Agent) Removal Guide

  Manual removal instructions: MSHAS32.EXE – Trojan Agent removal File MD5 Virus Alias MSHAS32.EXE 81a1a8f2735afa930c70eec3de4b6d57 Trojan Agent MSHAS32.EXE 81a1a8f2735afa930c70eec3de4b6d57 Trojan Small MSHAS32.EXE size: 386050 bytes MSHAS32.EXE hash: 81A1A8F2735AFA930C70EEC3DE4B6D57 Created files: %WinDir%\spoolsv.exe %SysDir%\concp32.exe %SysDir%\explorer.exe %SysDir%\mshas32.exe %SysDir%\vcl32.exe Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed Components\{E4883584-8B9A-11D5-EBA1-F78EEEEEE983}\StubPath: mshas32.exe HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VCL: vcl32.exe HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VCL: vcl32.exe Detected by UnHackMe: MSHAS32.EXE Default location: %SYSDIR%\MSHAS32.EXE Dropper information:…

Continue reading

Solved! Use CIS3.EXE (Trojan Hllw) Removal Guide

  Manual removal instructions: CIS3.EXE – Trojan Hllw removal File MD5 Virus Alias CIS3.EXE 6b8aaf95eec2b658c0b3be2cf9c7189e Trojan Hllw CIS3.EXE size: 108544 bytes CIS3.EXE hash: 6B8AAF95EEC2B658C0B3BE2CF9C7189E Created files: %Program Files%\Mozilla Firefox\firefox.xzg %Program Files%\MSN Gaming Zone\Windows\bckgzm.exe %Program Files%\MSN Gaming Zone\Windows\chkrzm.exe %Program Files%\NetMeeting\conf.bew %Program Files%\Vd2.exe %Program Files%\Windows NT\dialer.ogm %SysDir%\taskmgr.exe %SysDir%\VBoxService.exe %SysDir%\Winkber.exe %TEMP%\Aph7.exe %TEMP%\Cis3.exe %TEMP%\Fcg5.exe %TEMP%\Jnm4.exe %TEMP%\Qzm9.exe %TEMP%\Znf6.exe %TEMP%\Ztr8.exe \\VBOXSVR\in\Mdx.txt.exe…

Continue reading

Solved! Use ASBARBROKER.EXE (Unclassified Malware) Removal Guide

  Manual removal instructions: ASBARBROKER.EXE – Unclassified Malware removal ASBARBROKER.EXE size: 132536 bytes ASBARBROKER.EXE hash: D13F41376E40C08ECB42E05AEA68D57B Created files: %Program Files%\Baidu\AddressBar\AddressBar.dll %Program Files%\Baidu\AddressBar\ASBarBroker.exe %SysDir%\nnbdr.exe Detected by UnHackMe: ASBARBROKER.EXE Default location: %PROGRAM FILES%\BAIDU\ADDRESSBAR\ASBARBROKER.EXE Dropper information: MD5: d825621b5b5cd88c608bed39b34ba749 File size: 595456 bytes Vote as Harmless(0)Vote as Malicious(0)Remove it now! Recommended: UnHackMe anti-rootkit and anti-malware Premium software: RegRun Security…

Continue reading

Solved! Use OQNMNJ.SYS (Virus Sality) Removal Guide

  Manual removal instructions: OQNMNJ.SYS – Virus Sality removal File MD5 Virus Alias OQNMNJ.SYS 3ecc72712703b51f3cd4bcefe38ea758 Virus Sality OQNMNJ.SYS 3ecc72712703b51f3cd4bcefe38ea758 Trojan Agent OQNMNJ.SYS size: 5477 bytes OQNMNJ.SYS hash: 3ECC72712703B51F3CD4BCEFE38EA758 Created files: C:\KUKU400alpha %SysDir%\drivers\oqnmnj.sys %SysDir%\wmdrtc32.dll %SysDir%\wmdrtc32.dl_ %WinDir%\windows.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\PROGRAM: %WinDir%\WINDOWS.exe HKLM\System\CurrentControlSet\Services\NdisFileServices32\Type: 01000000 HKLM\System\CurrentControlSet\Services\NdisFileServices32\Start: 02000000 HKLM\System\CurrentControlSet\Services\NdisFileServices32\ErrorControl: 01000000 HKLM\System\CurrentControlSet\Services\NdisFileServices32\DisplayName: NdisFileServices32 HKLM\System\CurrentControlSet\Services\NdisFileServices32\ImagePath: %WinDir%\System32\drivers\oqnmnj.sys Detected by UnHackMe: OQNMNJ.SYS Default…

Continue reading

Solved! Use WINACPI.DLL (Trojan Agent) Removal Guide

  Manual removal instructions: WINACPI.DLL – Trojan Agent removal File MD5 Virus Alias WINACPI.DLL 077f1cafeddfe32273fb43d5a17198d4 Trojan Agent WINACPI.DLL 077f1cafeddfe32273fb43d5a17198d4 Trojan Generic WINACPI.DLL size: 55777 bytes WINACPI.DLL hash: 077F1CAFEDDFE32273FB43D5A17198D4 Created files: C:\windows\system32\mdms.exe C:\windows\system32\winacpi.dll Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SysMemory manager: c:\windows\System32\mdms.exe Detected by UnHackMe: WINACPI.DLL Default location: %SYSDIR%\WINACPI.DLL Dropper information: MD5: d800331d5773e9dbd5b3c42e6ef75a68 File size: 39393 bytes Vote as…

Continue reading

Solved! Use BSPLAYER V3.EXE (Trojan Small) Removal Guide

  Manual removal instructions: BSPLAYER V3.EXE – Trojan Small removal File MD5 Virus Alias BSPLAYER V3.EXE 714a48f3cd6aa36b64cfd6765c78cdc6 Trojan Small BSPLAYER V3.EXE 714a48f3cd6aa36b64cfd6765c78cdc6 Trojan Xema BSPLAYER V3.EXE 714a48f3cd6aa36b64cfd6765c78cdc6 Trojan Hllw BSPLAYER V3.EXE 714a48f3cd6aa36b64cfd6765c78cdc6 Trojan Eldorado BSPLAYER V3.EXE 714a48f3cd6aa36b64cfd6765c78cdc6 Trojan Agent BSPLAYER V3.EXE 714a48f3cd6aa36b64cfd6765c78cdc6 Trojan ADH BSPLAYER V3.EXE size: 2689356 bytes BSPLAYER V3.EXE hash: 714A48F3CD6AA36B64CFD6765C78CDC6 Created files:…

Continue reading

Solved! Use JNM4.EXE (Trojan Hllw) Removal Guide

  Manual removal instructions: JNM4.EXE – Trojan Hllw removal File MD5 Virus Alias JNM4.EXE da3abff2dd032b106663807c3ae58810 Trojan Hllw JNM4.EXE size: 108544 bytes JNM4.EXE hash: DA3ABFF2DD032B106663807C3AE58810 Created files: %Program Files%\Mozilla Firefox\firefox.xzg %Program Files%\MSN Gaming Zone\Windows\bckgzm.exe %Program Files%\MSN Gaming Zone\Windows\chkrzm.exe %Program Files%\NetMeeting\conf.bew %Program Files%\Vd2.exe %Program Files%\Windows NT\dialer.ogm %SysDir%\taskmgr.exe %SysDir%\VBoxService.exe %SysDir%\Winkber.exe %TEMP%\Aph7.exe %TEMP%\Cis3.exe %TEMP%\Fcg5.exe %TEMP%\Jnm4.exe %TEMP%\Qzm9.exe %TEMP%\Znf6.exe %TEMP%\Ztr8.exe \\VBOXSVR\in\Mdx.txt.exe…

Continue reading

Solved! Use NNBDR.EXE (Trojan (Suspicious File)) Removal Guide

  Manual removal instructions: NNBDR.EXE – Trojan (Suspicious File) removal File MD5 Virus Alias NNBDR.EXE 5866d30e73aba5f71f236b3585f83dfb Trojan (Suspicious File) NNBDR.EXE 5866d30e73aba5f71f236b3585f83dfb Trojan Downloader NNBDR.EXE size: 561797 bytes NNBDR.EXE hash: 5866D30E73ABA5F71F236B3585F83DFB Created files: %Program Files%\Baidu\AddressBar\AddressBar.dll %Program Files%\Baidu\AddressBar\ASBarBroker.exe %SysDir%\nnbdr.exe Detected by UnHackMe: NNBDR.EXE Default location: %SYSDIR%\NNBDR.EXE Dropper information: MD5: d825621b5b5cd88c608bed39b34ba749 File size: 595456 bytes Vote as Harmless(0)Vote…

Continue reading

Solved! Use DIBQFA.EXE (Trojan Shiz) Removal Guide

  Manual removal instructions: DIBQFA.EXE – Trojan Shiz removal File MD5 Virus Alias DIBQFA.EXE 84faf3ea9ae083f1cec7a2f7fb0df9ed Trojan Shiz DIBQFA.EXE 84faf3ea9ae083f1cec7a2f7fb0df9ed Trojan XPACK DIBQFA.EXE 84faf3ea9ae083f1cec7a2f7fb0df9ed Trojan Eldorado DIBQFA.EXE 84faf3ea9ae083f1cec7a2f7fb0df9ed Trojan Agent DIBQFA.EXE 84faf3ea9ae083f1cec7a2f7fb0df9ed Trojan Jorik DIBQFA.EXE 84faf3ea9ae083f1cec7a2f7fb0df9ed Trojan Crypt DIBQFA.EXE size: 272896 bytes DIBQFA.EXE hash: 84FAF3EA9AE083F1CEC7A2F7FB0DF9ED Created files: %WinDir%\apppatch\dibqfa.exe Detected by UnHackMe: DIBQFA.EXE Default location: %WinDir%\APPPATCH\DIBQFA.EXE Dropper…

Continue reading

Solved! Use REGSVR.EXE (Worm Autoit) Removal Guide

  Manual removal instructions: REGSVR.EXE – Worm Autoit removal File MD5 Virus Alias REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Worm Autoit REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Trojan Generic REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Trojan Hllw REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Trojan Eldorado REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Worm Autorun REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Trojan Agent REGSVR.EXE size: 2086656 bytes REGSVR.EXE hash: D837896D7B99589CF6FBFC589CD5E15D Created files: %WinDir%\regsvr.exe %SysDir%\28463\svchost.001 %SysDir%\regsvr.exe %SysDir%\svchost .exe Autostart registry keys: HKLM\Software\Microsoft\Windows…

Continue reading

Solved! Use SDHELP.EXE (Trojan Downloader) Removal Guide

  Manual removal instructions: SDHELP.EXE – Trojan Downloader removal File MD5 Virus Alias SDHELP.EXE d849786f1c4e63be024a6a3c7fcb8a00 Trojan Downloader SDHELP.EXE d849786f1c4e63be024a6a3c7fcb8a00 Trojan XPACK SDHELP.EXE d849786f1c4e63be024a6a3c7fcb8a00 Trojan Generic SDHELP.EXE d849786f1c4e63be024a6a3c7fcb8a00 Trojan Xema SDHELP.EXE d849786f1c4e63be024a6a3c7fcb8a00 Trojan Crypt SDHELP.EXE size: 15877 bytes SDHELP.EXE hash: D849786F1C4E63BE024A6A3C7FCB8A00 Created files: %SysDir%\IME\sdhelp.exe Autostart registry keys: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe “%WinDir%\System32\IME\sdhelp.exe” Detected by UnHackMe: SDHELP.EXE Default…

Continue reading

Solved! Use ZTR8.EXE (Trojan Hllw) Removal Guide

  Manual removal instructions: ZTR8.EXE – Trojan Hllw removal File MD5 Virus Alias ZTR8.EXE 4de5112aec5951f7ab3bd25db287c285 Trojan Hllw ZTR8.EXE size: 539136 bytes ZTR8.EXE hash: 4DE5112AEC5951F7AB3BD25DB287C285 Created files: %Program Files%\Mozilla Firefox\firefox.xzg %Program Files%\MSN Gaming Zone\Windows\bckgzm.exe %Program Files%\MSN Gaming Zone\Windows\chkrzm.exe %Program Files%\NetMeeting\conf.bew %Program Files%\Vd2.exe %Program Files%\Windows NT\dialer.ogm %SysDir%\taskmgr.exe %SysDir%\VBoxService.exe %SysDir%\Winkber.exe %TEMP%\Aph7.exe %TEMP%\Cis3.exe %TEMP%\Fcg5.exe %TEMP%\Jnm4.exe %TEMP%\Qzm9.exe %TEMP%\Znf6.exe %TEMP%\Ztr8.exe \\VBOXSVR\in\Mdx.txt.exe…

Continue reading

Solved! Use APH7.EXE (Trojan Hllw) Removal Guide

  Manual removal instructions: APH7.EXE – Trojan Hllw removal File MD5 Virus Alias APH7.EXE 0c3c46a9973646bd102ed5f9536d02dd Trojan Hllw APH7.EXE 0c3c46a9973646bd102ed5f9536d02dd Trojan Agent APH7.EXE size: 94108 bytes APH7.EXE hash: 0C3C46A9973646BD102ED5F9536D02DD Created files: %Program Files%\Mozilla Firefox\firefox.xzg %Program Files%\MSN Gaming Zone\Windows\bckgzm.exe %Program Files%\MSN Gaming Zone\Windows\chkrzm.exe %Program Files%\NetMeeting\conf.bew %Program Files%\Vd2.exe %Program Files%\Windows NT\dialer.ogm %SysDir%\taskmgr.exe %SysDir%\VBoxService.exe %SysDir%\Winkber.exe %TEMP%\Aph7.exe %TEMP%\Cis3.exe %TEMP%\Fcg5.exe %TEMP%\Jnm4.exe…

Continue reading

Solved! Use ADDRESSBAR.DLL (Trojan (Suspicious File)) Removal Guide

  Manual removal instructions: ADDRESSBAR.DLL – Trojan (Suspicious File) removal File MD5 Virus Alias ADDRESSBAR.DLL feaf384bd3c6520bd6ab6afb5a8a1ce8 Trojan (Suspicious File) ADDRESSBAR.DLL size: 1184176 bytes ADDRESSBAR.DLL hash: FEAF384BD3C6520BD6AB6AFB5A8A1CE8 Created files: %Program Files%\Baidu\AddressBar\AddressBar.dll %Program Files%\Baidu\AddressBar\ASBarBroker.exe %SysDir%\nnbdr.exe Detected by UnHackMe: ADDRESSBAR.DLL Default location: %PROGRAM FILES%\BAIDU\ADDRESSBAR\ADDRESSBAR.DLL Dropper information: MD5: d825621b5b5cd88c608bed39b34ba749 File size: 595456 bytes Vote as Harmless(0)Vote as Malicious(0)Remove it…

Continue reading

Solved! Use FCG5.EXE (Trojan Hllw) Removal Guide

  Manual removal instructions: FCG5.EXE – Trojan Hllw removal File MD5 Virus Alias FCG5.EXE 6c630be1ede2e058cd381fca98d693c2 Trojan Hllw FCG5.EXE 6c630be1ede2e058cd381fca98d693c2 Trojan Agent FCG5.EXE size: 96492 bytes FCG5.EXE hash: 6C630BE1EDE2E058CD381FCA98D693C2 Created files: %Program Files%\Mozilla Firefox\firefox.xzg %Program Files%\MSN Gaming Zone\Windows\bckgzm.exe %Program Files%\MSN Gaming Zone\Windows\chkrzm.exe %Program Files%\NetMeeting\conf.bew %Program Files%\Vd2.exe %Program Files%\Windows NT\dialer.ogm %SysDir%\taskmgr.exe %SysDir%\VBoxService.exe %SysDir%\Winkber.exe %TEMP%\Aph7.exe %TEMP%\Cis3.exe %TEMP%\Fcg5.exe %TEMP%\Jnm4.exe…

Continue reading

Solved! Use QZM9.EXE (Trojan Hllw) Removal Guide

  Manual removal instructions: QZM9.EXE – Trojan Hllw removal File MD5 Virus Alias QZM9.EXE 22088e3e7ad3017138e82b9baed6c6c5 Trojan Hllw QZM9.EXE size: 974848 bytes QZM9.EXE hash: 22088E3E7AD3017138E82B9BAED6C6C5 Created files: %Program Files%\Mozilla Firefox\firefox.xzg %Program Files%\MSN Gaming Zone\Windows\bckgzm.exe %Program Files%\MSN Gaming Zone\Windows\chkrzm.exe %Program Files%\NetMeeting\conf.bew %Program Files%\Vd2.exe %Program Files%\Windows NT\dialer.ogm %SysDir%\taskmgr.exe %SysDir%\VBoxService.exe %SysDir%\Winkber.exe %TEMP%\Aph7.exe %TEMP%\Cis3.exe %TEMP%\Fcg5.exe %TEMP%\Jnm4.exe %TEMP%\Qzm9.exe %TEMP%\Znf6.exe %TEMP%\Ztr8.exe \\VBOXSVR\in\Mdx.txt.exe…

Continue reading

Solved! Use MDMS.EXE (Trojan StartPage) Removal Guide

  Manual removal instructions: MDMS.EXE – Trojan StartPage removal File MD5 Virus Alias MDMS.EXE d800331d5773e9dbd5b3c42e6ef75a68 Trojan StartPage MDMS.EXE d800331d5773e9dbd5b3c42e6ef75a68 Trojan DLOADER MDMS.EXE d800331d5773e9dbd5b3c42e6ef75a68 Trojan (Suspicious File) MDMS.EXE d800331d5773e9dbd5b3c42e6ef75a68 Trojan Eldorado MDMS.EXE d800331d5773e9dbd5b3c42e6ef75a68 Trojan Downloader MDMS.EXE d800331d5773e9dbd5b3c42e6ef75a68 Trojan CI MDMS.EXE size: 39393 bytes MDMS.EXE hash: D800331D5773E9DBD5B3C42E6EF75A68 Created files: C:\windows\system32\mdms.exe C:\windows\system32\winacpi.dll Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SysMemory manager: c:\windows\System32\mdms.exe…

Continue reading

Solved! Use NFAPI.DLL (Trojan Artemis) Removal Guide

  Manual removal instructions: NFAPI.DLL – Trojan Artemis removal File MD5 Virus Alias NFAPI.DLL 04a835251535006c85473a604fba8bdc Trojan Artemis NFAPI.DLL 04a835251535006c85473a604fba8bdc Adware – Unwanted Program NFAPI.DLL 04a835251535006c85473a604fba8bdc Trojan Generic NFAPI.DLL 04a835251535006c85473a604fba8bdc Trojan Downloader NFAPI.DLL size: 126976 bytes NFAPI.DLL hash: 04A835251535006C85473A604FBA8BDC Created files: %Program Files%\WNet\libeay32.dll %Program Files%\WNet\nfapi.dll %Program Files%\WNet\ProtocolFilters.dll %Program Files%\WNet\ssleay32.dll %Program Files%\WNet\WNet.exe Detected by UnHackMe: NFAPI.DLL Default…

Continue reading

Solved! Use SSLEAY32.DLL (Unclassified Malware) Removal Guide

  Manual removal instructions: SSLEAY32.DLL – Unclassified Malware removal SSLEAY32.DLL size: 376832 bytes SSLEAY32.DLL hash: 2DA6E9DF4979CA65A01C4DF6EB5600D2 Created files: %Program Files%\WNet\libeay32.dll %Program Files%\WNet\nfapi.dll %Program Files%\WNet\ProtocolFilters.dll %Program Files%\WNet\ssleay32.dll %Program Files%\WNet\WNet.exe Detected by UnHackMe: SSLEAY32.DLL Default location: %PROGRAM FILES%\WNET\SSLEAY32.DLL Dropper information: MD5: 265db905b900bcc65d8cd299fadd9521 File size: 1267224 bytes Vote as Harmless(0)Vote as Malicious(0)Remove it now! Recommended: UnHackMe anti-rootkit and…

Continue reading

Solved! Use WNET.EXE (Trojan Delf) Removal Guide

  Manual removal instructions: WNET.EXE – Trojan Delf removal File MD5 Virus Alias WNET.EXE 45571677457a9bfd49aadada0fd91ca8 Trojan Delf WNET.EXE size: 436736 bytes WNET.EXE hash: 45571677457A9BFD49AADADA0FD91CA8 Created files: %Program Files%\WNet\libeay32.dll %Program Files%\WNet\nfapi.dll %Program Files%\WNet\ProtocolFilters.dll %Program Files%\WNet\ssleay32.dll %Program Files%\WNet\WNet.exe Detected by UnHackMe: WNET.EXE Default location: %PROGRAM FILES%\WNET\WNET.EXE Dropper information: MD5: 265db905b900bcc65d8cd299fadd9521 File size: 1267224 bytes Vote as Harmless(0)Vote…

Continue reading

Solved! Use PROTOCOLFILTERS.DLL (Adware – Unwanted Program) Removal Guide

  Manual removal instructions: PROTOCOLFILTERS.DLL – Adware – Unwanted Program removal File MD5 Virus Alias PROTOCOLFILTERS.DLL fab8104ced422c551bcf2dda631e5930 Adware – Unwanted Program PROTOCOLFILTERS.DLL fab8104ced422c551bcf2dda631e5930 Trojan, Suspicious File PROTOCOLFILTERS.DLL fab8104ced422c551bcf2dda631e5930 Trojan Generic PROTOCOLFILTERS.DLL fab8104ced422c551bcf2dda631e5930 Trojan Agent PROTOCOLFILTERS.DLL size: 368640 bytes PROTOCOLFILTERS.DLL hash: FAB8104CED422C551BCF2DDA631E5930 Created files: %Program Files%\WNet\libeay32.dll %Program Files%\WNet\nfapi.dll %Program Files%\WNet\ProtocolFilters.dll %Program Files%\WNet\ssleay32.dll %Program Files%\WNet\WNet.exe Detected by…

Continue reading

Solved! Use BBOFAA.EXE (Trojan Downloader) Removal Guide

  Manual removal instructions: BBOFAA.EXE – Trojan Downloader removal File MD5 Virus Alias BBOFAA.EXE d87992886d3ddabbd453eef2bb9f4940 Trojan Downloader BBOFAA.EXE d87992886d3ddabbd453eef2bb9f4940 Trojan ModifiedUPX BBOFAA.EXE d87992886d3ddabbd453eef2bb9f4940 Trojan Generic BBOFAA.EXE d87992886d3ddabbd453eef2bb9f4940 Trojan Eldorado BBOFAA.EXE d87992886d3ddabbd453eef2bb9f4940 Trojan Kazy BBOFAA.EXE d87992886d3ddabbd453eef2bb9f4940 Trojan Renos BBOFAA.EXE size: 507392 bytes BBOFAA.EXE hash: D87992886D3DDABBD453EEF2BB9F4940 Created files: %WinDir%\Bbofaa.exe Detected by UnHackMe: BBOFAA.EXE Default location: %WinDir%\BBOFAA.EXE Dropper…

Continue reading

Solved! Use IVVHUM.EXE (Trojan Crypt) Removal Guide

  Manual removal instructions: IVVHUM.EXE – Trojan Crypt removal File MD5 Virus Alias IVVHUM.EXE 7dd03b4e3e5c00da8ae53d6dbe556b54 Trojan Crypt IVVHUM.EXE 7dd03b4e3e5c00da8ae53d6dbe556b54 Trojan Siggen IVVHUM.EXE size: 10459 bytes IVVHUM.EXE hash: 7DD03B4E3E5C00DA8AE53D6DBE556B54 Created files: %SysDir%\ivvhum.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\m.exe: %WinDir%\System32\ivvhum.exeS Detected by UnHackMe: IVVHUM.EXE Default location: %SYSDIR%\IVVHUM.EXE Dropper information: MD5: d87795846d5c6eb6e802329b41c10f80 File size: 311371 bytes Vote as Harmless(0)Vote as…

Continue reading

Solved! Use UPDATE.EXE (Trojan Agent) Removal Guide

  Manual removal instructions: UPDATE.EXE – Trojan Agent removal File MD5 Virus Alias UPDATE.EXE 1e1f429c61e4652e2fd6a90979e4247f Trojan Agent UPDATE.EXE 1e1f429c61e4652e2fd6a90979e4247f Trojan Generic UPDATE.EXE 1e1f429c61e4652e2fd6a90979e4247f Trojan Downloader UPDATE.EXE size: 593920 bytes UPDATE.EXE hash: 1E1F429C61E4652E2FD6A90979E4247F Created files: %Program Files%\softupdate\clsca.exe %Program Files%\softupdate\db\ui.bin %Program Files%\softupdate\db\update.bin %Program Files%\softupdate\db\update.exe %Program Files%\softupdate\ui.bin %Program Files%\softupdate\update.bin %Program Files%\softupdate\update.exe Detected by UnHackMe: UPDATE.EXE Default location: %PROGRAM…

Continue reading

Solved! Use DEXTOR32.EXE (Unknown) Removal Guide

  Manual removal instructions: DEXTOR32.EXE – Unknown removal DEXTOR32.EXE size: 129864 bytes DEXTOR32.EXE hash: D624921342FDB988A9D7E08B65809E80 Created files: %WinDir%\dextor32.exe %WinDir%\Temp\AikaQuest3Hentai FullDownloader.exe %WinDir%\Temp\AIM Account Stealer Downloader.exe %WinDir%\Temp\Battle.net key generator (WORKS!!).exe %WinDir%\Temp\Borland Delphi 6 Key Generator.exe %WinDir%\Temp\Britney spears nude.exe %WinDir%\Temp\Cat Attacks Child Full Downloader.exe %WinDir%\Temp\CKY3 – Bam Margera World Industries Alien Workshop Full Downloader.exe %WinDir%\Temp\DivX.exe %WinDir%\Temp\DSL Modem Uncapper.exe…

Continue reading

Solved! Use WINHOST.EXE (Trojan Swisyn) Removal Guide

  Manual removal instructions: WINHOST.EXE – Trojan Swisyn removal File MD5 Virus Alias WINHOST.EXE d607315985b421cd3235775f29991300 Trojan Swisyn WINHOST.EXE d607315985b421cd3235775f29991300 Trojan Artemis WINHOST.EXE d607315985b421cd3235775f29991300 Trojan MLW WINHOST.EXE d607315985b421cd3235775f29991300 Trojan Click WINHOST.EXE d607315985b421cd3235775f29991300 Trojan Downloader WINHOST.EXE d607315985b421cd3235775f29991300 Trojan CI WINHOST.EXE size: 16384 bytes WINHOST.EXE hash: D607315985B421CD3235775F29991300 Created files: C:\winhost.exe Detected by UnHackMe: WINHOST.EXE Default location: C:\WINHOST.EXE Dropper…

Continue reading

Solved! Use CJXFQXGOPE.EXE (Trojan Crypt) Removal Guide

  Manual removal instructions: CJXFQXGOPE.EXE – Trojan Crypt removal File MD5 Virus Alias CJXFQXGOPE.EXE 3fd99b178aab28b5d5401d9df3cae020 Trojan Crypt CJXFQXGOPE.EXE 3fd99b178aab28b5d5401d9df3cae020 Trojan Siggen CJXFQXGOPE.EXE size: 10459 bytes CJXFQXGOPE.EXE hash: 3FD99B178AAB28B5D5401D9DF3CAE020 Created files: %SysDir%\cjxfqxgope.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\e.exe: %WinDir%\System32\cjxfqxgope.exe? Detected by UnHackMe: CJXFQXGOPE.EXE Default location: %SYSDIR%\CJXFQXGOPE.EXE Dropper information: MD5: d8766361990a42727cf11fbb2ab0dcd0 File size: 20003 bytes Vote as Harmless(0)Vote as…

Continue reading

Solved! Use BASSMOD.DLL (Trojan (Suspicious File)) Removal Guide

  Manual removal instructions: BASSMOD.DLL – Trojan (Suspicious File) removal File MD5 Virus Alias BASSMOD.DLL e4ec57e8508c5c4040383ebe6d367928 Trojan (Suspicious File) BASSMOD.DLL size: 34308 bytes BASSMOD.DLL hash: E4EC57E8508C5C4040383EBE6D367928 Created files: %SysDir%\BASSMOD.dll Detected by UnHackMe: BASSMOD.DLL Default location: %SYSDIR%\BASSMOD.DLL Dropper information: MD5: d8577418758dc9bc7e4e095ffebbb03b File size: 66560 bytes Vote as Harmless(0)Vote as Malicious(0)Remove it now! Recommended: UnHackMe anti-rootkit and…

Continue reading

Solved! Use VCMGCD32.DLL (Virus Sality) Removal Guide

  Manual removal instructions: VCMGCD32.DLL – Virus Sality removal File MD5 Virus Alias VCMGCD32.DLL ae22ca9f11ade8e362254b452cc07f78 Virus Sality VCMGCD32.DLL ae22ca9f11ade8e362254b452cc07f78 Trojan Agent VCMGCD32.DLL size: 36864 bytes VCMGCD32.DLL hash: AE22CA9F11ADE8E362254B452CC07F78 Created files: C:\KUKU300a %WinDir%\java.exe %WinDir%\services.exe %SysDir%\vcmgcd32.dll %SysDir%\vcmgcd32.dl_ %Local AppData%\Google\Update\GoogleUpdate.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\JavaVM: %WinDir%\java.exe HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Services: %WinDir%\services.exe Detected by UnHackMe: VCMGCD32.DLL Default location: %SYSDIR%\VCMGCD32.DLL Dropper information: MD5: d85400708386423c45eae64cc830cf8b…

Continue reading

Solved! Use .EXE (Worm Vobfus) Removal Guide

  Manual removal instructions: .EXE – Worm Vobfus removal File MD5 Virus Alias .EXE 724f6ac07e70c802ec319d4885a0895e Worm Vobfus .EXE 724f6ac07e70c802ec319d4885a0895e Trojan Generic .EXE 724f6ac07e70c802ec319d4885a0895e Trojan Siggen .EXE 724f6ac07e70c802ec319d4885a0895e Worm Pronny .EXE 724f6ac07e70c802ec319d4885a0895e Trojan Crypt .EXE size: 47494 bytes .EXE hash: 724F6AC07E70C802EC319D4885A0895E Created files: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\ .exe C:\My Shared Documents.exe %WinDir%\system\wincirl.com %SysDir%\SVCH0ST.EXE D:\Recycled.exe \\vboxsrv\in\TEST.exe…

Continue reading

Solved! Use F3EZSETP.DLL (Adware MyWebSearch) Removal Guide

  Manual removal instructions: F3EZSETP.DLL – Adware MyWebSearch removal File MD5 Virus Alias F3EZSETP.DLL 39fe674fd759af4978cd519a1a0b7c34 Adware MyWebSearch F3EZSETP.DLL 39fe674fd759af4978cd519a1a0b7c34 Trojan (Suspicious File) F3EZSETP.DLL 39fe674fd759af4978cd519a1a0b7c34 Trojan Generic F3EZSETP.DLL 39fe674fd759af4978cd519a1a0b7c34 Adware FunWeb F3EZSETP.DLL 39fe674fd759af4978cd519a1a0b7c34 Trojan Click F3EZSETP.DLL 39fe674fd759af4978cd519a1a0b7c34 Trojan Downloader F3EZSETP.DLL size: 90112 bytes F3EZSETP.DLL hash: 39FE674FD759AF4978CD519A1A0B7C34 Created files: %Program Files%\FunWebProducts\Installr\1.bin\F3EZSETP.DLL Detected by UnHackMe: F3EZSETP.DLL Default location:…

Continue reading

Solved! Use KQHQBN.DLL (Trojan PcClient) Removal Guide

  Manual removal instructions: KQHQBN.DLL – Trojan PcClient removal File MD5 Virus Alias KQHQBN.DLL 8662ee3a20923cb56ddf4e1cff4eac1e Trojan PcClient KQHQBN.DLL 8662ee3a20923cb56ddf4e1cff4eac1e Trojan Generic KQHQBN.DLL 8662ee3a20923cb56ddf4e1cff4eac1e Trojan Eldorado KQHQBN.DLL 8662ee3a20923cb56ddf4e1cff4eac1e Trojan Downloader KQHQBN.DLL 8662ee3a20923cb56ddf4e1cff4eac1e Backdoor PcClien KQHQBN.DLL 8662ee3a20923cb56ddf4e1cff4eac1e Backdoor Hupigon KQHQBN.DLL size: 73216 bytes KQHQBN.DLL hash: 8662EE3A20923CB56DDF4E1CFF4EAC1E Created files: %Program Files Common%\Microsoft Shared\kqhqbn.dll %Program Files Common%\Microsoft Shared\kqhqbn.exe %Temp%\kqhqbn.dll…

Continue reading

Solved! Use CPUSH.DLL (Trojan Click) Removal Guide

  Manual removal instructions: CPUSH.DLL – Trojan Click removal File MD5 Virus Alias CPUSH.DLL 61f7fc215f9e63b315fac41ac2d4ac74 Trojan Click CPUSH.DLL 61f7fc215f9e63b315fac41ac2d4ac74 Trojan (Suspicious File) CPUSH.DLL size: 176128 bytes CPUSH.DLL hash: 61F7FC215F9E63B315FAC41AC2D4AC74 Created files: %Program Files Common%\CPUSH\cpush.dll %Program Files Common%\CPUSH\Uninst.exe Detected by UnHackMe: CPUSH.DLL Default location: %PROGRAM FILES COMMON%\CPUSH\CPUSH.DLL Dropper information: MD5: d875473481658c898e351ba786ae9c30 File size: 115143 bytes Vote…

Continue reading

Solved! Use RECYCLED.EXE (Worm Vobfus) Removal Guide

  Manual removal instructions: RECYCLED.EXE – Worm Vobfus removal File MD5 Virus Alias RECYCLED.EXE 724f6ac07e70c802ec319d4885a0895e Worm Vobfus RECYCLED.EXE 724f6ac07e70c802ec319d4885a0895e Trojan Generic RECYCLED.EXE 724f6ac07e70c802ec319d4885a0895e Trojan Siggen RECYCLED.EXE 724f6ac07e70c802ec319d4885a0895e Worm Pronny RECYCLED.EXE 724f6ac07e70c802ec319d4885a0895e Trojan Crypt RECYCLED.EXE size: 47494 bytes RECYCLED.EXE hash: 724F6AC07E70C802EC319D4885A0895E Created files: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\ .exe C:\My Shared Documents.exe %WinDir%\system\wincirl.com %SysDir%\SVCH0ST.EXE D:\Recycled.exe \\vboxsrv\in\TEST.exe…

Continue reading

Solved! Use WINCIRL.COM (Worm Vobfus) Removal Guide

  Manual removal instructions: WINCIRL.COM – Worm Vobfus removal File MD5 Virus Alias WINCIRL.COM d7876030295d0c615efdabe63f97eb20 Worm Vobfus WINCIRL.COM d7876030295d0c615efdabe63f97eb20 Trojan Generic WINCIRL.COM d7876030295d0c615efdabe63f97eb20 Trojan Siggen WINCIRL.COM d7876030295d0c615efdabe63f97eb20 Virus Sality WINCIRL.COM d7876030295d0c615efdabe63f97eb20 Worm Pronny WINCIRL.COM d7876030295d0c615efdabe63f97eb20 Trojan Crypt WINCIRL.COM size: 47232 bytes WINCIRL.COM hash: D7876030295D0C615EFDABE63F97EB20 Created files: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\ .exe C:\My Shared Documents.exe…

Continue reading

Solved! Use SVCH0ST.EXE (Worm Vobfus) Removal Guide

  Manual removal instructions: SVCH0ST.EXE – Worm Vobfus removal File MD5 Virus Alias SVCH0ST.EXE d7876030295d0c615efdabe63f97eb20 Worm Vobfus SVCH0ST.EXE d7876030295d0c615efdabe63f97eb20 Trojan Generic SVCH0ST.EXE d7876030295d0c615efdabe63f97eb20 Trojan Siggen SVCH0ST.EXE d7876030295d0c615efdabe63f97eb20 Virus Sality SVCH0ST.EXE d7876030295d0c615efdabe63f97eb20 Worm Pronny SVCH0ST.EXE d7876030295d0c615efdabe63f97eb20 Trojan Crypt SVCH0ST.EXE size: 47232 bytes SVCH0ST.EXE hash: D7876030295D0C615EFDABE63F97EB20 Created files: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\ .exe C:\My Shared Documents.exe…

Continue reading

Solved! Use MY SHARED DOCUMENTS.EXE (Worm Vobfus) Removal Guide

  Manual removal instructions: MY SHARED DOCUMENTS.EXE – Worm Vobfus removal File MD5 Virus Alias MY SHARED DOCUMENTS.EXE 724f6ac07e70c802ec319d4885a0895e Worm Vobfus MY SHARED DOCUMENTS.EXE 724f6ac07e70c802ec319d4885a0895e Trojan Generic MY SHARED DOCUMENTS.EXE 724f6ac07e70c802ec319d4885a0895e Trojan Siggen MY SHARED DOCUMENTS.EXE 724f6ac07e70c802ec319d4885a0895e Worm Pronny MY SHARED DOCUMENTS.EXE 724f6ac07e70c802ec319d4885a0895e Trojan Crypt MY SHARED DOCUMENTS.EXE size: 47494 bytes MY SHARED DOCUMENTS.EXE hash:…

Continue reading

Solved! Use INSTALLERHELPER.DLL (Trojan Agent) Removal Guide

  Manual removal instructions: INSTALLERHELPER.DLL – Trojan Agent removal File MD5 Virus Alias INSTALLERHELPER.DLL 3e025efcbad009f0a6d30fb0a45f3fab Trojan Agent INSTALLERHELPER.DLL 3e025efcbad009f0a6d30fb0a45f3fab Adware (Unwanted Program) INSTALLERHELPER.DLL 3e025efcbad009f0a6d30fb0a45f3fab Trojan Generic INSTALLERHELPER.DLL 3e025efcbad009f0a6d30fb0a45f3fab Adware Downware INSTALLERHELPER.DLL 3e025efcbad009f0a6d30fb0a45f3fab Trojan Downloader INSTALLERHELPER.DLL 3e025efcbad009f0a6d30fb0a45f3fab Trojan Krap INSTALLERHELPER.DLL size: 135680 bytes INSTALLERHELPER.DLL hash: 3E025EFCBAD009F0A6D30FB0A45F3FAB Created files: C:\dccbf1dd-39fd-4dcd-a1b5-1626acc81e90\InstallerHelper.dll C:\dccbf1dd-39fd-4dcd-a1b5-1626acc81e90\start.hta Detected by UnHackMe: INSTALLERHELPER.DLL Default location:…

Continue reading

Solved! Use KQHQBN.EXE (Trojan PcClient) Removal Guide

  Manual removal instructions: KQHQBN.EXE – Trojan PcClient removal File MD5 Virus Alias KQHQBN.EXE d77664714071d172b02eacea5e6d63a0 Trojan PcClient KQHQBN.EXE d77664714071d172b02eacea5e6d63a0 Trojan Generic KQHQBN.EXE d77664714071d172b02eacea5e6d63a0 Trojan Eldorado KQHQBN.EXE d77664714071d172b02eacea5e6d63a0 Backdoor PcClien KQHQBN.EXE d77664714071d172b02eacea5e6d63a0 Trojan Agent KQHQBN.EXE d77664714071d172b02eacea5e6d63a0 Backdoor IRCBot KQHQBN.EXE size: 90624 bytes KQHQBN.EXE hash: D77664714071D172B02EACEA5E6D63A0 Created files: %Program Files Common%\Microsoft Shared\kqhqbn.dll %Program Files Common%\Microsoft Shared\kqhqbn.exe %Temp%\kqhqbn.dll…

Continue reading

Solved! Use NETUSBENV.EXE (Trojan Agent) Removal Guide

  Manual removal instructions: NETUSBENV.EXE – Trojan Agent removal File MD5 Virus Alias NETUSBENV.EXE d7438623119c7893a36aa966b01afea5 Trojan Agent NETUSBENV.EXE d7438623119c7893a36aa966b01afea5 Trojan Generic NETUSBENV.EXE d7438623119c7893a36aa966b01afea5 Trojan Hllw NETUSBENV.EXE size: 2217259 bytes NETUSBENV.EXE hash: D7438623119C7893A36AA966B01AFEA5 Created files: %SysDir%\apifwsql.exe %SysDir%\apimgrfs.exe %SysDir%\netusbenv.exe %SysDir%\objlibui.exe %SysDir%\schdwintapi.ocx %SysDir%\spoolcds.dll %SysDir%\themeuichk.dll %SysDir%\uiwdmsvc.exe %SysDir%\winpdbdhcp.exe %Temp%\advsec32.dll Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\StubPath: rundll32.exe %WinDir%\System32\themeuichk.dll,ThemesSetupInstallCheck HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\IconsBinary:…

Continue reading

Solved! Use APIMGRFS.EXE (Trojan Agent) Removal Guide

  Manual removal instructions: APIMGRFS.EXE – Trojan Agent removal File MD5 Virus Alias APIMGRFS.EXE d7438623119c7893a36aa966b01afea5 Trojan Agent APIMGRFS.EXE d7438623119c7893a36aa966b01afea5 Trojan Generic APIMGRFS.EXE d7438623119c7893a36aa966b01afea5 Trojan Hllw APIMGRFS.EXE size: 2217259 bytes APIMGRFS.EXE hash: D7438623119C7893A36AA966B01AFEA5 Created files: %SysDir%\apifwsql.exe %SysDir%\apimgrfs.exe %SysDir%\netusbenv.exe %SysDir%\objlibui.exe %SysDir%\schdwintapi.ocx %SysDir%\spoolcds.dll %SysDir%\themeuichk.dll %SysDir%\uiwdmsvc.exe %SysDir%\winpdbdhcp.exe %Temp%\advsec32.dll Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\StubPath: rundll32.exe %WinDir%\System32\themeuichk.dll,ThemesSetupInstallCheck HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\IconsBinary:…

Continue reading

Solved! Use WINPDBDHCP.EXE (Trojan Agent) Removal Guide

  Manual removal instructions: WINPDBDHCP.EXE – Trojan Agent removal File MD5 Virus Alias WINPDBDHCP.EXE d7438623119c7893a36aa966b01afea5 Trojan Agent WINPDBDHCP.EXE d7438623119c7893a36aa966b01afea5 Trojan Generic WINPDBDHCP.EXE d7438623119c7893a36aa966b01afea5 Trojan Hllw WINPDBDHCP.EXE size: 2217259 bytes WINPDBDHCP.EXE hash: D7438623119C7893A36AA966B01AFEA5 Created files: %SysDir%\apifwsql.exe %SysDir%\apimgrfs.exe %SysDir%\netusbenv.exe %SysDir%\objlibui.exe %SysDir%\schdwintapi.ocx %SysDir%\spoolcds.dll %SysDir%\themeuichk.dll %SysDir%\uiwdmsvc.exe %SysDir%\winpdbdhcp.exe %Temp%\advsec32.dll Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\StubPath: rundll32.exe %WinDir%\System32\themeuichk.dll,ThemesSetupInstallCheck HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\IconsBinary:…

Continue reading

Solved! Use OBJLIBUI.EXE (Trojan Agent) Removal Guide

  Manual removal instructions: OBJLIBUI.EXE – Trojan Agent removal File MD5 Virus Alias OBJLIBUI.EXE 16f881ca44448ec16734cc0775529413 Trojan Agent OBJLIBUI.EXE 16f881ca44448ec16734cc0775529413 Trojan Hllw OBJLIBUI.EXE size: 2217259 bytes OBJLIBUI.EXE hash: 16F881CA44448EC16734CC0775529413 Created files: %SysDir%\apifwsql.exe %SysDir%\apimgrfs.exe %SysDir%\netusbenv.exe %SysDir%\objlibui.exe %SysDir%\schdwintapi.ocx %SysDir%\spoolcds.dll %SysDir%\themeuichk.dll %SysDir%\uiwdmsvc.exe %SysDir%\winpdbdhcp.exe %Temp%\advsec32.dll Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\StubPath: rundll32.exe %WinDir%\System32\themeuichk.dll,ThemesSetupInstallCheck HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\IconsBinary: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0061007000690066007700730071006C002E006500780065000000 HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\Version:…

Continue reading

Solved! Use NMBHMA.EXE (Backdoor Nitol) Removal Guide

  Manual removal instructions: NMBHMA.EXE – Backdoor Nitol removal File MD5 Virus Alias NMBHMA.EXE d7557159165000bd9134072e5114f1a7 Backdoor Nitol NMBHMA.EXE d7557159165000bd9134072e5114f1a7 Trojan DLOADER NMBHMA.EXE d7557159165000bd9134072e5114f1a7 Trojan Artemis NMBHMA.EXE d7557159165000bd9134072e5114f1a7 Trojan MLW NMBHMA.EXE d7557159165000bd9134072e5114f1a7 Trojan Eldorado NMBHMA.EXE d7557159165000bd9134072e5114f1a7 Trojan Downloader NMBHMA.EXE size: 109604 bytes NMBHMA.EXE hash: D7557159165000BD9134072E5114F1A7 Created files: %SysDir%\nmbhma.exe Autostart registry keys: HKLM\System\CurrentControlSet\Services\Nationaltlw\Type: 10000000 HKLM\System\CurrentControlSet\Services\Nationaltlw\Start: 02000000 HKLM\System\CurrentControlSet\Services\Nationaltlw\DisplayName:…

Continue reading

Solved! Use UIWDMSVC.EXE (Trojan Agent) Removal Guide

  Manual removal instructions: UIWDMSVC.EXE – Trojan Agent removal File MD5 Virus Alias UIWDMSVC.EXE d7438623119c7893a36aa966b01afea5 Trojan Agent UIWDMSVC.EXE d7438623119c7893a36aa966b01afea5 Trojan Generic UIWDMSVC.EXE d7438623119c7893a36aa966b01afea5 Trojan Hllw UIWDMSVC.EXE size: 2217259 bytes UIWDMSVC.EXE hash: D7438623119C7893A36AA966B01AFEA5 Created files: %SysDir%\apifwsql.exe %SysDir%\apimgrfs.exe %SysDir%\netusbenv.exe %SysDir%\objlibui.exe %SysDir%\schdwintapi.ocx %SysDir%\spoolcds.dll %SysDir%\themeuichk.dll %SysDir%\uiwdmsvc.exe %SysDir%\winpdbdhcp.exe %Temp%\advsec32.dll Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\StubPath: rundll32.exe %WinDir%\System32\themeuichk.dll,ThemesSetupInstallCheck HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\IconsBinary:…

Continue reading

Solved! Use SCHDWINTAPI.OCX (Trojan Genome) Removal Guide

  Manual removal instructions: SCHDWINTAPI.OCX – Trojan Genome removal File MD5 Virus Alias SCHDWINTAPI.OCX 3adea70969f52d365c119b3d25619de9 Trojan Genome SCHDWINTAPI.OCX 3adea70969f52d365c119b3d25619de9 Trojan Generic SCHDWINTAPI.OCX 3adea70969f52d365c119b3d25619de9 Trojan Click SCHDWINTAPI.OCX 3adea70969f52d365c119b3d25619de9 Trojan Agent SCHDWINTAPI.OCX size: 4096 bytes SCHDWINTAPI.OCX hash: 3ADEA70969F52D365C119B3D25619DE9 Created files: %SysDir%\apifwsql.exe %SysDir%\apimgrfs.exe %SysDir%\netusbenv.exe %SysDir%\objlibui.exe %SysDir%\schdwintapi.ocx %SysDir%\spoolcds.dll %SysDir%\themeuichk.dll %SysDir%\uiwdmsvc.exe %SysDir%\winpdbdhcp.exe %Temp%\advsec32.dll Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\StubPath: rundll32.exe…

Continue reading

Solved! Use APIFWSQL.EXE (Trojan Agent) Removal Guide

  Manual removal instructions: APIFWSQL.EXE – Trojan Agent removal File MD5 Virus Alias APIFWSQL.EXE d7438623119c7893a36aa966b01afea5 Trojan Agent APIFWSQL.EXE d7438623119c7893a36aa966b01afea5 Trojan Generic APIFWSQL.EXE d7438623119c7893a36aa966b01afea5 Trojan Hllw APIFWSQL.EXE size: 2217259 bytes APIFWSQL.EXE hash: D7438623119C7893A36AA966B01AFEA5 Created files: %SysDir%\apifwsql.exe %SysDir%\apimgrfs.exe %SysDir%\netusbenv.exe %SysDir%\objlibui.exe %SysDir%\schdwintapi.ocx %SysDir%\spoolcds.dll %SysDir%\themeuichk.dll %SysDir%\uiwdmsvc.exe %SysDir%\winpdbdhcp.exe %Temp%\advsec32.dll Autostart registry keys: HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\StubPath: rundll32.exe %WinDir%\System32\themeuichk.dll,ThemesSetupInstallCheck HKLM\Software\Microsoft\Active Setup\Installed Components\{22d7f312-b0f6-11d2-94ab-0080c33c7e95}\IconsBinary:…

Continue reading

Solved! Use IEXPLOREI.EXE (Virus Alman) Removal Guide

  Manual removal instructions: IEXPLOREI.EXE – Virus Alman removal File MD5 Virus Alias IEXPLOREI.EXE d72096262972c5003f3c9f08093539a0 Virus Alman IEXPLOREI.EXE d72096262972c5003f3c9f08093539a0 Worm Autoit IEXPLOREI.EXE d72096262972c5003f3c9f08093539a0 Trojan Agent IEXPLOREI.EXE size: 658432 bytes IEXPLOREI.EXE hash: D72096262972C5003F3C9F08093539A0 Created files: %WinDir%\IEXPLOREi.exe %WinDir%\linkinfo.dll %SysDir%\drivers\IsDrv122.sys %SysDir%\IEXPLOREi.exe %SysDir%\WORD.exe Autostart registry keys: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe IEXPLOREi.exe HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Yahoo Messengger: %WinDir%\System32\IEXPLOREi.exe Detected by UnHackMe: IEXPLOREI.EXE Default location:…

Continue reading

Solved! Use STRY.EXE (Trojan Delphi) Removal Guide

  Manual removal instructions: STRY.EXE – Trojan Delphi removal File MD5 Virus Alias STRY.EXE 45dbee9825fb742512f70fd9b29e1159 Trojan Delphi STRY.EXE 45dbee9825fb742512f70fd9b29e1159 Trojan Generic STRY.EXE 45dbee9825fb742512f70fd9b29e1159 Trojan Hllw STRY.EXE 45dbee9825fb742512f70fd9b29e1159 Trojan Eldorado STRY.EXE 45dbee9825fb742512f70fd9b29e1159 Trojan Agent STRY.EXE size: 513402 bytes STRY.EXE hash: 45DBEE9825FB742512F70FD9B29E1159 Created files: C:\BFFB.EXE C:\Documents and Settings\AJGY.EXE C:\Documents and Settings\NRTNR.EXE C:\Documents and Settings\STRY.EXE C:\filedebug %Program Files%\RXSVQ.EXE…

Continue reading

Solved! Use TPQ.EXE (Trojan Delphi) Removal Guide

  Manual removal instructions: TPQ.EXE – Trojan Delphi removal File MD5 Virus Alias TPQ.EXE 5628ba49c6445566f731614295249948 Trojan Delphi TPQ.EXE 5628ba49c6445566f731614295249948 Trojan Generic TPQ.EXE 5628ba49c6445566f731614295249948 Trojan Hllw TPQ.EXE 5628ba49c6445566f731614295249948 Trojan Eldorado TPQ.EXE 5628ba49c6445566f731614295249948 Trojan Agent TPQ.EXE size: 513264 bytes TPQ.EXE hash: 5628BA49C6445566F731614295249948 Created files: C:\BFFB.EXE C:\Documents and Settings\AJGY.EXE C:\Documents and Settings\NRTNR.EXE C:\Documents and Settings\STRY.EXE C:\filedebug %Program Files%\RXSVQ.EXE…

Continue reading

Solved! Use ZNHUI.EXE (Trojan Delphi) Removal Guide

  Manual removal instructions: ZNHUI.EXE – Trojan Delphi removal File MD5 Virus Alias ZNHUI.EXE 3f65ac539da6fad84b7065096a5b7b26 Trojan Delphi ZNHUI.EXE 3f65ac539da6fad84b7065096a5b7b26 Trojan Generic ZNHUI.EXE 3f65ac539da6fad84b7065096a5b7b26 Trojan Hllw ZNHUI.EXE 3f65ac539da6fad84b7065096a5b7b26 Trojan Eldorado ZNHUI.EXE 3f65ac539da6fad84b7065096a5b7b26 Trojan Agent ZNHUI.EXE size: 513613 bytes ZNHUI.EXE hash: 3F65AC539DA6FAD84B7065096A5B7B26 Created files: C:\BFFB.EXE C:\Documents and Settings\AJGY.EXE C:\Documents and Settings\NRTNR.EXE C:\Documents and Settings\STRY.EXE C:\filedebug %Program Files%\RXSVQ.EXE…

Continue reading

Solved! Use KCOJNHJK.DLL (Trojan Eldorado) Removal Guide

  Manual removal instructions: KCOJNHJK.DLL – Trojan Eldorado removal File MD5 Virus Alias KCOJNHJK.DLL 574c4039393430d0e10e6f7c394fdf99 Trojan Eldorado KCOJNHJK.DLL size: 6657 bytes KCOJNHJK.DLL hash: 574C4039393430D0E10E6F7C394FDF99 Created files: %SysDir%\Kcojnhjk.dll %SysDir%\Pbbpkeoh.exe Autostart registry keys: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ctfmon.exe: %WinDir%\System32\ctfmon.exe Detected by UnHackMe: KCOJNHJK.DLL Default location: %SYSDIR%\KCOJNHJK.DLL Dropper information: MD5: d6987861721f1a7f50f24c388dae4010 File size: 52736 bytes Vote as Harmless(0)Vote as Malicious(0)Remove it now!…

Continue reading

Solved! Use PBBPKEOH.EXE (Trojan PAK_Generic) Removal Guide

  Manual removal instructions: PBBPKEOH.EXE – Trojan PAK_Generic removal File MD5 Virus Alias PBBPKEOH.EXE 4c215914334e113b01cd4e7987388705 Trojan PAK_Generic PBBPKEOH.EXE 4c215914334e113b01cd4e7987388705 Trojan Eldorado PBBPKEOH.EXE 4c215914334e113b01cd4e7987388705 Trojan Agent PBBPKEOH.EXE 4c215914334e113b01cd4e7987388705 Trojan Crypt PBBPKEOH.EXE size: 52736 bytes PBBPKEOH.EXE hash: 4C215914334E113B01CD4E7987388705 Created files: %SysDir%\Kcojnhjk.dll %SysDir%\Pbbpkeoh.exe Autostart registry keys: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ctfmon.exe: %WinDir%\System32\ctfmon.exe Detected by UnHackMe: PBBPKEOH.EXE Default location: %SYSDIR%\PBBPKEOH.EXE Dropper information: MD5:…

Continue reading

Solved! Use XALJKBY.EXE (Trojan Delphi) Removal Guide

  Manual removal instructions: XALJKBY.EXE – Trojan Delphi removal File MD5 Virus Alias XALJKBY.EXE c00c1e4eb0798316dda097d16fc79858 Trojan Delphi XALJKBY.EXE c00c1e4eb0798316dda097d16fc79858 Trojan Generic XALJKBY.EXE c00c1e4eb0798316dda097d16fc79858 Trojan Hllw XALJKBY.EXE c00c1e4eb0798316dda097d16fc79858 Trojan Eldorado XALJKBY.EXE c00c1e4eb0798316dda097d16fc79858 Trojan Agent XALJKBY.EXE size: 514046 bytes XALJKBY.EXE hash: C00C1E4EB0798316DDA097D16FC79858 Created files: C:\BFFB.EXE C:\Documents and Settings\AJGY.EXE C:\Documents and Settings\NRTNR.EXE C:\Documents and Settings\STRY.EXE C:\filedebug %Program Files%\RXSVQ.EXE…

Continue reading

Solved! Use TLP.EXE (Trojan Delphi) Removal Guide

  Manual removal instructions: TLP.EXE – Trojan Delphi removal File MD5 Virus Alias TLP.EXE 99bdce85b4ce5fe3dc5a16ef519ef984 Trojan Delphi TLP.EXE 99bdce85b4ce5fe3dc5a16ef519ef984 Trojan Generic TLP.EXE 99bdce85b4ce5fe3dc5a16ef519ef984 Trojan Hllw TLP.EXE 99bdce85b4ce5fe3dc5a16ef519ef984 Trojan Eldorado TLP.EXE 99bdce85b4ce5fe3dc5a16ef519ef984 Trojan Agent TLP.EXE size: 514126 bytes TLP.EXE hash: 99BDCE85B4CE5FE3DC5A16EF519EF984 Created files: C:\BFFB.EXE C:\Documents and Settings\AJGY.EXE C:\Documents and Settings\NRTNR.EXE C:\Documents and Settings\STRY.EXE C:\filedebug %Program Files%\RXSVQ.EXE…

Continue reading