VSPROPLUS.EXE – Trojan SuspiciousFile

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

VSPROPLUS.EXE – Trojan SuspiciousFile removal

FileMD5Virus Alias
VSPROPLUS.EXE df8835cf1f2b22a7a1db62bd1ae2b9d4 Trojan SuspiciousFile

VSPROPLUS.EXE size: 86528 bytes
VSPROPLUS.EXE hash: DF8835CF1F2B22A7A1DB62BD1AE2B9D4

Created files:

%Program Files%\VSpro\Helper64.exe
%Program Files%\VSpro\msstdfmt.dll
%Program Files%\VSpro\msvcp100.dll
%Program Files%\VSpro\msvcp100d.dll
%Program Files%\VSpro\msvcr100.dll
%Program Files%\VSpro\msvcr100d.dll
%Program Files%\VSpro\NovinSoft.exe
%Program Files%\VSpro\p
%Program Files%\VSpro\PM9.exe
%Program Files%\VSpro\Profiles\Default.ppx
%Program Files%\VSpro\Proxifier.exe
%Program Files%\VSpro\ProxyChecker.exe
%Program Files%\VSpro\PrxDrvPE.dll
%Program Files%\VSpro\PrxDrvPE64.dll
%Program Files%\VSpro\Settings.dll
%Program Files%\VSpro\tunnelplus.dll
%Program Files%\VSpro\vsproplus\4758cca.dll
%Program Files%\VSpro\vsproplus\aep.dll
%Program Files%\VSpro\vsproplus\atalla.dll
%Program Files%\VSpro\vsproplus\capi.dll
%Program Files%\VSpro\vsproplus\chil.dll
%Program Files%\VSpro\vsproplus\cswift.dll
%Program Files%\VSpro\vsproplus\gmp.dll
%Program Files%\VSpro\vsproplus\gost.dll
%Program Files%\VSpro\vsproplus\libeay32.dll
%Program Files%\VSpro\vsproplus\msvcr90.dll
%Program Files%\VSpro\vsproplus\nuron.dll
%Program Files%\VSpro\vsproplus\padlock.dll
%Program Files%\VSpro\vsproplus\ssleay32.dll
%Program Files%\VSpro\vsproplus\sureware.dll
%Program Files%\VSpro\vsproplus\ubsec.dll
%Program Files%\VSpro\vsproplus\vsproplus.exe
%Program Files%\VSpro\vsproplus\zlib1.dll
%Program Files%\VSpro\xmllite.dll
%SysDir%\msstdfmt.dll
%SysDir%\msvcp100.dll
%SysDir%\msvcp100d.dll
%SysDir%\msvcr100.dll
%SysDir%\msvcr100d.dll
%TEMP%\aiw2201295.EXE
%WinDir%\VSpro Uninstaller.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\RasMan\Parameters\ProhibitIpSec: 01000000

Detected by UnHackMe:

VSPROPLUS.EXE
Default location: %PROGRAM FILES%\VSPRO\VSPROPLUS\VSPROPLUS.EXE

Dropper information:
MD5: 48ac4f53a4963739b40de4e2fde3ee63
File size: 7710048 bytes

Leave a Reply