I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
HQFORM.OCX – Trojan CI removal
File | MD5 | Virus Alias |
---|---|---|
HQFORM.OCX | 1562a162322a65da30769088b2608981 | Trojan CI |
HQFORM.OCX size: 1733120 bytes
Created files:
%WinDir%\Downloaded Program Files\fileBrowse.ocx
%WinDir%\Downloaded Program Files\hqext.ocx
%WinDir%\Downloaded Program Files\hqform.ocx
%SysDir%\hqpub.dll
%SysDir%\organisation.dll
%SysDir%\RunScan.exe
%SysDir%\WebScan.dll
%TEMP%\RarSFX0\AtxSetup.exe
%TEMP%\RarSFX0\FileBrowse.ocx
%TEMP%\RarSFX0\hqext.ocx
%TEMP%\RarSFX0\HqForm.ocx
%TEMP%\RarSFX0\HQPub.dll
%TEMP%\RarSFX0\organisation.dll
%TEMP%\RarSFX0\RunScan.exe
%TEMP%\RarSFX0\WebScan.dll
Autostart registry keys:
HKLM\Software\Classes\CLSID\{3D1DF513-AF71-4D26-BEAE-15EA88B07398}\InprocServer32 : %WinDir%\DOWNLO~1\FILEBR~1.OCX
HKLM\Software\Classes\CLSID\{9FB6F190-E8BF-4D17-8B12-1AB5BDFE7BB0}\InprocServer32 : %WinDir%\DOWNLO~1\FILEBR~1.OCX
HKLM\Software\Classes\CLSID\{A806F6BB-473C-4EF2-B7E0-8EE15F781AC4}\InprocServer32 : %WinDir%\DOWNLO~1\hqext.ocx
HKLM\Software\Classes\CLSID\{E593373C-B16E-4F66-9D98-A82E59333622}\InprocServer32 : %WinDir%\DOWNLO~1\hqform.ocx
HKLM\Software\Classes\CLSID\{FE70C9C0-FB4D-4225-A50D-F967EC8FC54A}\InprocServer32 : %WinDir%\DOWNLO~1\hqext.ocx
Detected by UnHackMe:
HQFORM.OCX
Default location: %TEMP%\RARSFX0\HQFORM.OCX