UNINSTALL.EXE – Trojan WS.Reputation

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

UNINSTALL.EXE – Trojan WS.Reputation removal

FileMD5Virus Alias
UNINSTALL.EXE 75e74faf34472af72dbd675cd6a0fb78 Trojan WS.Reputation
UNINSTALL.EXE 75e74faf34472af72dbd675cd6a0fb78 Trojan Qhost

UNINSTALL.EXE size: 57386 bytes
UNINSTALL.EXE hash: 75E74FAF34472AF72DBD675CD6A0FB78

Created files:

%Program Files%\Utilocean\COMDLG32.OCX
%Program Files%\Utilocean\Uninstall.exe
%Program Files%\Utilocean\utiloceandn.exe
%Program Files%\Utilocean\utiloceanup.exe
%SysDir%\INETKO.DLL
%WinDir%\utiloceansetup.exe

Autostart registry keys:

HKLM\Software\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Utilocean\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Utilocean\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{3C4F3BE7-47EB-101B-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Utilocean\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59294-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59295-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Utilocean\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Utilocean\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32 : %Program Files%\Utilocean\COMDLG32.OCX
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UtilOcean: %Program Files%\Utilocean\utiloceanup.exe

Detected by UnHackMe:

UNINSTALL.EXE
Default location: %PROGRAM FILES%\UTILOCEAN\UNINSTALL.EXE

Dropper information:
MD5: 97a4520398a90bcf49803a89644e9e53
File size: 950152 bytes

Leave a Reply