I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
FILEOCEANDN.EXE – Trojan SuspiciousFile removal
File | MD5 | Virus Alias |
---|---|---|
FILEOCEANDN.EXE | e389a9f286bd96e62e1f5be93a183807 | Trojan SuspiciousFile |
FILEOCEANDN.EXE size: 135048 bytes
FILEOCEANDN.EXE hash: E389A9F286BD96E62E1F5BE93A183807
Created files:
%Program Files%\Fileocean\COMDLG32.OCX
%Program Files%\Fileocean\fileoceandn.exe
%Program Files%\Fileocean\oceanfiledn.exe
%Program Files%\Fileocean\Uninstall.exe
%WinDir%\oceansetup.exe
%SysDir%\INETKO.DLL
Autostart registry keys:
HKLM\Software\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Fileocean\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Fileocean\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{3C4F3BE7-47EB-101B-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Fileocean\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59294-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59295-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Fileocean\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Fileocean\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Fileocean\COMDLG32.OCX
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\FileOcean: %Program Files%\Fileocean\fileoceandn.exe
Detected by UnHackMe:
FILEOCEANDN.EXE
Default location: %PROGRAM FILES%\FILEOCEAN\FILEOCEANDN.EXE
Dropper information:
MD5: be9020ae154817f88e194293fe7b0844
File size: 950152 bytes