QXBSTKWFX.SCR

QXBSTKWFX.SCR

The file QXBSTKWFX.scr has internal name: SDRootAlyzer.exe. The file QXBSTKWFX.scr description is: Rootkit scanner. The file QXBSTKWFX.scr is related to the Safer-Networking Ltd.. The version of the file QXBSTKWFX.scr: 2.0.9.116. The QXBSTKWFX.scr is a part of software product: Spybot – Search & Destroy LegalCopyright: ? 2008-2012 Safer-Networking Ltd. All rights reserved..
The file QXBSTKWFX.scr size is: 3 912 736 bytes.
Default location: %Program Files%\Spybot – Search & Destroy 2\QXBSTKWFX.scr
QXBSTKWFX.scr MD5: EA932C3B977A5941FF220951C05981E1
QXBSTKWFX.scr SHA1: D5B6BD45 829D57F9 AA0623D7 E8F08943 99E8C589

Registry strings in the QXBSTKWFX.scr:

\SOFTWARE\Microsoft\Windows\CurrentVersion\
\Software\Microsoft\Windows\CurrentVersion\Explorer
\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\
\Software\Microsoft\Windows\CurrentVersion\RunOnce
\Software\Safer Networking Limited\Games\Knight Hop\
MACHINE,”\Software\Microsoft\Windows\CurrentVersion\”,”HidingSpywareValue”
Software\CLASSES\CLSID\
Software\madshi\ContactForm
Software\Microsoft\Windows
Software\Microsoft\Windows NT\CurrentVersion\
Software\Microsoft\Windows\CurrentVersion\
Software\Microsoft\Windows\CurrentVersion\Installer\
Software\Microsoft\Windows\CurrentVersion\Setup\
Software\Wow6432Node\
System\CurrentControlSet\Services\
USER,”\Software\Example.com\RecentFiles”
USER,”\Software\Microsoft\Internet Explorer\Main\”,”Save Directory=”
USER,\SOFTWARE\,”Spyware”

The QXBSTKWFX.SCR related files:
advapi32.dll comctl32.dll comdlg32.dll crypt32.dll gdi32.dll kernel32.dll ModuleUsage:”spyware/spyware.dllnetapi32.dll ole32.dll oleaut32.dll SharedDLL:library.dll shell32.dll SYSDIR>\spyware.dlluser32.dll utildll.dll version.dll WINDIR>\*.exe“,”:malware: wininet.dll winmm.dll wsock32.dll

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit is required. Reviews. EULA. Privacy Policy.

Leave a Reply