Category Archives: Virus

not-a-virus:RiskTool.Win32.StartPage.khy

not-a-virus:RiskTool.Win32.StartPage.khy also known as DR/Autoit.hjf, Dropper.AutoIt, W32.HfsAtITIST.DC24. Malware Analysis of not-a-virus:RiskTool.Win32.StartPage.khy – IJZRQAP.EXE Created files: %PROFILE%\FAVORITES\????.URL %Program Files%\360\360safe\deepscan\speedmem2.hg %TEMP%\IJZRQAP.EXE %PROFILE%\FAVORITES\9.9??.URL %PROFILE%\FAVORITES\LINKS\9.9??.URL Autostart registry keys: HKLM\Software\Classes\CLSID\{B5EAD1DB-7C18-4954-8820-01733BC08C82}\shell\Open\Command\: “”%Program Files%\Internet Explorer\iexplore.exe”” Detected by UnHackMe: IJZRQAP.EXE DEFAULT LOCATION: %TEMP%\IJZRQAP.EXE Dropper hash(md5): 08e611f02490d7caf28ae9727ff2e4cd UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100%…

Continue reading

not-a-virus:NetTool.Win64.NetFilter.mp

not-a-virus:NetTool.Win64.NetFilter.mp also known as Risktool.Win64.Netfilter!c. Malware Analysis of not-a-virus:NetTool.Win64.NetFilter.mp – WEISETUNNEL64.DLL Created files: %TEMP%\RARSFXPC\WINDOWS\WEISETUNNEL.DLL %TEMP%\RARSFXPC\WINDOWS\WEISETUNNEL.EXE %TEMP%\RARSFXPC\WINDOWS\WEISETUNNEL64.DLL %TEMP%\RARSFXPC\WINDOWS\WEISEWD.SYS %TEMP%\RARSFXPC\WINDOWS\WEISEWD.SYS.WIN7 Detected by UnHackMe: WEISETUNNEL64.DLL DEFAULT LOCATION: %TEMP%\RARSFXPC\WINDOWS\WEISETUNNEL64.DLL Dropper hash(md5): edb43c94f3610701c8995e51cc0259ac UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain any form of…

Continue reading

Win32/Virus.RiskTool.cc4

Win32/Virus.RiskTool.cc4 also known as Risktool.Win64.Netfilter!c. Malware Analysis of Win32/Virus.RiskTool.cc4 – WEISETUNNEL64.DLL Created files: %TEMP%\RARSFXPC\WINDOWS\WEISETUNNEL.DLL %TEMP%\RARSFXPC\WINDOWS\WEISETUNNEL.EXE %TEMP%\RARSFXPC\WINDOWS\WEISETUNNEL64.DLL %TEMP%\RARSFXPC\WINDOWS\WEISEWD.SYS %TEMP%\RARSFXPC\WINDOWS\WEISEWD.SYS.WIN7 Detected by UnHackMe: WEISETUNNEL64.DLL DEFAULT LOCATION: %TEMP%\RARSFXPC\WINDOWS\WEISETUNNEL64.DLL Dropper hash(md5): edb43c94f3610701c8995e51cc0259ac UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain any form of…

Continue reading

virus.win32.mabezat.b

virus.win32.mabezat.b also known as Trojan.Win32.Generic!O, Trojan ( 00010d641 ), Malware.Heuristic!ET#100% (rdm+). Malware Analysis of virus.win32.mabezat.b – YQYZZT.EXE Created files: %TEMP%\SKYP\SERVER.EXE %TEMP%\TIEBKI.EXE %TEMP%\YQYZZT.EXE %STARTUP%\UPDATE.LNK Detected by UnHackMe: YQYZZT.EXE DEFAULT LOCATION: %TEMP%\YQYZZT.EXE Dropper hash(md5): 13023322441f821401b09cb658bb4dff UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does…

Continue reading

W32.eHeur.Virus04

W32.eHeur.Virus04 also known as Backdoor/Delf.yvd. Malware Analysis of W32.eHeur.Virus04 – AMULE-2.3.1-INSTALLER.EXE Created files: %PROFILE%\DESKTOP\AMULE REMOTE GUI.LNK %PROFILE%\DESKTOP\AMULE.LNK %PROFILE%\DOWNLOADS\AMULE-2.3.1-INSTALLER.EXE %PROFILE%\DOWNLOADS\AMULE-2.3.2\ABOUT-NLS %PROFILE%\DOWNLOADS\AMULE-2.3.2\ACINCLUDE.M4 Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\aMule\DisplayName: “aMule” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\aMule\UninstallString: “%Program Files%\aMule\uninstall.exe” Detected by UnHackMe: AMULE-2.3.1-INSTALLER.EXE DEFAULT LOCATION: %PROFILE%\DOWNLOADS\AMULE-2.3.1-INSTALLER.EXE Dropper hash(md5): db283a14afb2ee1548e29346ad0d8490 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100%…

Continue reading

Virus.Win32.Induc.A

Virus.Win32.Induc.A also known as W32.eHeur.Malware09, Win32.Induc.b.820224, Virus.Win32.Induc.a (v). Malware Analysis of Virus.Win32.Induc.A – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe:…

Continue reading

Virus.Win32.Induc

Virus.Win32.Induc also known as Virus.Induc!1.9B53 (classic), Virus.Win32.Induct.1!O, Virus.Win32.Induc.c. Malware Analysis of Virus.Win32.Induc – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe:…

Continue reading

Virus ( f10009011 )

Virus ( f10009011 ) also known as Win32.Induc.A, W32/Induc.A. Malware Analysis of Virus ( f10009011 ) – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC…

Continue reading

Virus.Induc!1.9B53 (classic)

Virus.Induc!1.9B53 (classic) also known as Win.Virus.Induc-2, W32.Induc.A, Win32/Induc.a. Malware Analysis of Virus.Induc!1.9B53 (classic) – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by…

Continue reading

Win.Virus.TeslaCrypt3_AntiVss-1

Win.Virus.TeslaCrypt3_AntiVss-1 also known as Trojan.ShadowDeleter, Ransom:Win32/Tescrypt.J, Trojan.Deshacop.jo. Malware Analysis of Win.Virus.TeslaCrypt3_AntiVss-1 – JWABO.EXE Created files: %APPDATA%\MOZILLA\FIREFOX\PROFILES\J3CZWNGH.DEFAULT\SITESECURITYSERVICESTATE.TXT.MP3 %APPDATA%\MOZILLA\FIREFOX\PROFILES\RECOVERY+YQPYN.PNG %PROFILE%\DOCUMENTS\JWABO.EXE %PROFILE%\DOCUMENTS\RECOVER_FILE_TPRQEQCQF.TXT %SYSTEMDRIVE%\USERS\RECOVERY+YQPYN.HTML Autostart registry keys: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\12_23-DST: “%WINDIR%\YHWRMBSDARYV.EXE” Detected by UnHackMe: JWABO.EXE DEFAULT LOCATION: %PROFILE%\DOCUMENTS\JWABO.EXE Dropper hash(md5): d7f25ad7ffdca8585c1ff260ddf0f78e UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means…

Continue reading

Virus.Win32.Induc.b

Virus.Win32.Induc.b also known as Virus.Induc.Win32.1, W32.Induc.A, W32.eHeur.Malware09. Malware Analysis of Virus.Win32.Induc.b – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe: IPODPCTRANSFER.EXE…

Continue reading

Virus:Win32/Induc.A

Virus:Win32/Induc.A also known as Virus.Win32.Induc.dffkeg, Win32/Induc, Generic Malware. Malware Analysis of Virus:Win32/Induc.A – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe:…

Continue reading

Virus.Win32.Induc.c

Virus.Win32.Induc.c also known as W32.eHeur.Malware09, PE_INDUC.A, Win32.Induc.A. Malware Analysis of Virus.Win32.Induc.c – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe: IPODPCTRANSFER.EXE…

Continue reading

Win.Virus.Induc-2

Win.Virus.Induc-2 also known as W32/Induc, Win32.Induc.A, Virus.Win32.Induc. Malware Analysis of Win.Virus.Induc-2 – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe: IPODPCTRANSFER.EXE…

Continue reading

Virus.Induc.Win32.1

Virus.Induc.Win32.1 also known as Win32.Induc.A, Virus.Win32.Induc.a (v), Win32.Induc.A[h]. Malware Analysis of Virus.Induc.Win32.1 – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe:…

Continue reading

Virus/Win32.Induc.b

Virus/Win32.Induc.b also known as Win32.Virus.Induc.a, Win32/Induc, Virus ( f10009011 ). Malware Analysis of Virus/Win32.Induc.b – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected…

Continue reading

Virus.Win32.Induc.dffkeg

Virus.Win32.Induc.dffkeg also known as W32.Induc.A, Virus.Win32.Induc.a (v), Win32.Induc.A. Malware Analysis of Virus.Win32.Induc.dffkeg – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe:…

Continue reading

Win32.Virus.Induc.a

Win32.Virus.Induc.a also known as Virus/W32.Induc, Virus:Win32/Induc.A, W32.Induc.A. Malware Analysis of Win32.Virus.Induc.a – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe: IPODPCTRANSFER.EXE…

Continue reading

Virus.Win32.Induc.a (v)

Virus.Win32.Induc.a (v) also known as W32.eHeur.Malware09, Win32.Induc.A, BehavesLike.Win32.Dropper.th. Malware Analysis of Virus.Win32.Induc.a (v) – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by…

Continue reading

Virus/W32.Induc

Virus/W32.Induc also known as Generic Malware, Win32.Induc.A, Virus.Win32.Induc. Malware Analysis of Virus/W32.Induc – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe:…

Continue reading

Virus.Win32.Induct.1!O

Virus.Win32.Induct.1!O also known as W32/Induc.A, Win.Virus.Induc-2, Virus/W32.Induc. Malware Analysis of Virus.Win32.Induct.1!O – IPODPCTRANSFER.EXE Created files: %PUBLIC%\DESKTOP\IPOD PC TRANSFER.LNK %Program Files%\iPod PC Transfer\const.idx %Program Files%\iPod PC Transfer\IpodPcTransfer.exe %Program Files%\iPod PC Transfer\ipodpthlp.chm %Program Files%\iPod PC Transfer\unins000.dat Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\DisplayName: “iPod PC Transfer 4.2” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iPod PC Transfer_is1\UninstallString: “”%Program Files%\iPod PC Transfer\unins000.exe”” Detected by UnHackMe: IPODPCTRANSFER.EXE…

Continue reading

virus.win32.ramnit.ah

virus.win32.ramnit.ah also known as HW32.Packed.B203, Heur.Malware-Cryptor.Multiplug. MALWARE ANALYSIS OF VIRUS.WIN32.RAMNIT.AH – F3EEA75E10D89D799E0D097F2A4CB698.EXE Created files: %COMMON APPDATA%\{7F6B0E0D-0BAB-5282-7F6B-B0E0D0BA3834}\F8ED9290838BA9A3 %COMMON APPDATA%\{7F6B0E0D-0BAB-5282-7F6B-B0E0D0BA3834}\F3EEA75E10D89D799E0D097F2A4CB698.DAT %COMMON APPDATA%\{7F6B0E0D-0BAB-5282-7F6B-B0E0D0BA3834}\F3EEA75E10D89D799E0D097F2A4CB698.EXE %SYSDIR%\TASKS\ENERGYSAVER %WINDIR%\TASKS\ENERGYSAVER.JOB Detected by UnHackMe: F3EEA75E10D89D799E0D097F2A4CB698.EXE DEFAULT LOCATION: %COMMON APPDATA%\{7F6B0E0D-0BAB-5282-7F6B-B0E0D0BA3834}\F3EEA75E10D89D799E0D097F2A4CB698.EXE Dropper hash(md5): f3eea75e10d89d799e0d097f2a4cb698 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does…

Continue reading

BrowserModifier.RestrictsUser.r5 (Not a Virus)

BrowserModifier.RestrictsUser.r5 (Not a Virus) also known as W32/Adware.FENE-8781, Trojan.Win32.Generic!BT, Adware.Win32.BHO.40. Malware Analysis of BrowserModifier.RestrictsUser.r5 (Not a Virus) – R7U61.DLL Created files: %APPDATA%\MOZILLA\FIREFOX\PROFILES\J3CZWNGH.DEFAULT\EXTENSIONS\STAGED\OUU5_ST@YUHKJWP-.NET\CONTENT\BG.JS %APPDATA%\MOZILLA\FIREFOX\PROFILES\J3CZWNGH.DEFAULT\EXTENSIONS\STAGED\OUU5_ST@YUHKJWP-.NET\INSTALL.RDF %COMMON APPDATA%\SAIFOE, SAVUE\R7U61.DLL %COMMON APPDATA%\SAIFOE, SAVUE\R7U61.TLB %COMMON APPDATA%\SAIFOE, SAVUE\SETTINGS.INI Autostart registry keys: HKLM\SOFTWARE\CLASSES\CLSID\{56D7AA8D-40CA-821A-6178-08E60ECDC6B9}\INPROCSERVER32\: “%COMMON APPDATA%\SAIFOE, SAVUE\R7U61.DLL” HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{924C3DC2-8E4E-432E-F973-9A2174A39774}\UNINSTALLSTRING: “”REGSVR32.EXE” /S /N /I:”EXECUTECOMMANDS;UNINSTALLCOMMANDS” “%COMMON APPDATA%\SAIFOE, SAVUE\YIE15.DLL”” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{924C3DC2-8E4E-432E-F973-9A2174A39774}\DisplayName: “saifoe, SaVue” Detected by UnHackMe: R7U61.DLL DEFAULT…

Continue reading

virus.win32.ramnit.a

virus.win32.ramnit.a also known as Malware.Undefined!8.C-qHjzCq7DvuQ (cloud), PUA.ClientConnect, a variant of Win32/Toolbar.Conduit.B potentially unwanted. Malware Analysis of virus.win32.ramnit.a – GLF4C14.TMP.TBMYWE.DLL Created files: %TEMP%\8D126940DD4E174B44115CC1736ADA66.JSON %TEMP%\GLF4C14.TMP.CONDUITENGINESETUP.EXE %TEMP%\GLF4C14.TMP.TBMYWE.DLL %TEMP%\GLF55B9.TMP.CONDUITENGINE.DLL %TEMP%\MYWEBSITES.PRO-ES.EXE Autostart registry keys: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\DisplayName: “mywebsites.pro-ES Customized Web Search” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine\DisplayName: “Conduit Engine” HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CONDUITENGINE\UNINSTALLSTRING: “%SYSTEMDRIVE%\PROGRA~1\CONDUI~1\CONDUITENGINEUNINSTALL.EXE” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\mywebsites.pro-ES Toolbar\DisplayName: “mywebsites.pro-ES Toolbar” HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MYWEBSITES.PRO-ES TOOLBAR\UNINSTALLSTRING: “%SYSTEMDRIVE%\PROGRA~1\MYWEBS~1.PRO\UNWISE.EXE /U %SYSTEMDRIVE%\PROGRA~1\MYWEBS~1.PRO\INSTALL.LOG ” HKLM\Software\conduitEngine\toolbar\DisplayName: “Conduit Engine” HKLM\Software\mywebsites.pro-ES\toolbar\DisplayName: “mywebsites.pro-ES”…

Continue reading

Win32/Virus.951

Win32/Virus.951 also known as Pua.Gen!c, Adware.Win32.InstallCore.ba (v), a variant of Win32/Injected.F. MALWARE ANALYSIS OF WIN32/VIRUS.951 – ICREINSTALL_85B481EA37F1A6BCF4B7D168D7A08B59.EXE Created files: %Program Files%\Google\Chrome\Application\54.0.2840.99\WidevineCdm\_platform_specific\win_x86\widevinecdm.dll %Program Files%\Google\Chrome\Application\54.0.2840.99\WidevineCdm\_platform_specific\win_x86\widevinecdmadapter.dll %TEMP%\ICREINSTALL_85B481EA37F1A6BCF4B7D168D7A08B59.EXE %TEMP%\IS1293689599\57435_STP.EXE %TEMP%\ISH50312\CSS\IE6_MAIN.CSS Detected by UnHackMe: ICREINSTALL_85B481EA37F1A6BCF4B7D168D7A08B59.EXE DEFAULT LOCATION: %TEMP%\ICREINSTALL_85B481EA37F1A6BCF4B7D168D7A08B59.EXE Dropper hash(md5): 85b481ea37f1a6bcf4b7d168d7a08b59 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which…

Continue reading

Virus.B32.Gen!c

Virus.B32.Gen!c also known as Adware.Nieguide.75680[h], Adware ( 004d92921 ), Adware.Nieguide.Win32.80. Malware Analysis of Virus.B32.Gen!c – KSMODULE.DLL Created files: %Program Files%\AHNSOFT\ancamera3\ancamera5.exe %Program Files%\AHNSOFT\ancamera3\ancameraup.exe %Program Files%\AHNSOFT\ancamera3\ksmodule.dll %Program Files%\AHNSOFT\ancamera3\Uninstall.exe %Program Files%\AHNSOFT\ancamera3\updatelist.ini Autostart registry keys: HKLM\Software\Classes\CLSID\{F1A015C9-8106-4120-9D18-21BAEDAB20FF}\InprocServer32\: “%Program Files%\AHNSOFT\ancamera3\ksmodule.dll” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\AnCamCorder\DisplayName: “AnCamCorder Uninstall” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\AnCamCorder\UninstallString: “%Program Files%\\AHNSOFT\AnCamCorder\Uninstall.exe” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\AnCamera\DisplayName: “Ancamera Uninstall” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\AnCamera\UninstallString: “%Program Files%\AHNSOFT\ancamera3\Uninstall.exe” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antools\DisplayName: “Antools” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antools\UninstallString: “”%Program Files%\AHNSOFT\Antools\Uninstall.exe”” Detected by UnHackMe: KSMODULE.DLL…

Continue reading

Virus ( f10001f11 )

Virus ( f10001f11 ) also known as . Malware Analysis of Virus ( f10001f11 ) – VMSAFEUKGIURPN.EXE Created files: %TEMP%\360INIVERIFY.INI %TEMP%\CMZRNNYYUBSTKNSB\{73000F29-A1D3-494E-9F1C-54B267848B3A}.TMP %TEMP%\CQGJEYSGZGYSOWWL\VMSAFEUKGIURPN.EXE %TEMP%\DALOBPZEVLONVKZF.TMP %TEMP%\EUQNBVDQWMVMNURP.TMP Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\91GameBox2_is1\DisplayName: “91GameBox2 1.1.4” HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\91GameBox2_is1\UninstallString: “”%Program Files%\Ks91Gamebox\UninsFiles\unins000.exe”” HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\BAIDUSERVICE.EXE\IMAGEPATH: “%LOCAL APPDATA%\BAIDU\BAIDUCLIENT\3.0.200.2787\BAIDUSERVICE.EXE” HKLM\System\CurrentControlSet\services\BaiduService.exe\DisplayName: “BaiduService.exe” HKLM\System\CurrentControlSet\services\bbnetdriver\ImagePath: “\SystemRoot\system32\drivers\bbnetdriver.sys” HKLM\System\CurrentControlSet\services\bbnetdriver\DisplayName: “bbnetdriver” HKLM\System\CurrentControlSet\services\bbnetservice\ImagePath: “%SystemRoot%\system32\svchost.exe -k bbnetservice” HKLM\System\CurrentControlSet\services\bbnetservice\DisplayName: “bbnetservice” HKCU\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\AEPPGFLJJLHCNNBDDCCCNDLJODPDKPDH\PATH: “%LOCAL APPDATA%\HT1HAO\HT1HAOAPP\\EXTENSIONS\EXTENSIONCHROME.CRX” HKCU\Software\Google\Chrome\Extensions\aeppgfljjlhcnnbddcccndljodpdkpdh\Version: “2.1.0” HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Ks91Gameboxrun: “”%Program…

Continue reading

Win32.Virus.Virut.Lpvd

Win32.Virus.Virut.Lpvd also known as Trojan.Win32.Generic!BT, Trojan-Spy.Dyzap, W32/Waldek.SYI!tr. Malware Analysis of Win32.Virus.Virut.Lpvd – 270F78.EXE Created files: %COMMON APPDATA%\MICROSOFT\VAULT\AC658CB4-9126-49BD-B877-31EEDAB3F204\2F1A6504-0641-44CF-8BB5-3612D865F2E5.VSCH %COMMON APPDATA%\MICROSOFT\VAULT\AC658CB4-9126-49BD-B877-31EEDAB3F204\3CCD5499-87A8-4B10-A215-608888DD3B55.VSCH %COMMON APPDATA%\MICROSOFT\VAULT\AC658CB4-9126-49BD-B877-31EEDAB3F204\POLICY.VPOL %LOCAL APPDATA%\MICROSOFT\VAULT\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\POLICY.VPOL %APPDATA%\518812\270F78.EXE Detected by UnHackMe: 270F78.EXE DEFAULT LOCATION: %APPDATA%\518812\270F78.EXE Dropper hash(md5): abb98c3e24322c74447804663f90cb66 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it…

Continue reading

Virus.F7D.Gen!c

Virus.F7D.Gen!c also known as Riskware ( 0040eff71 ), Generic.F7D, BrowserModifier:Win32/Xiazai. Malware Analysis of Virus.F7D.Gen!c – SOCKET2.DLL Created files: %TEMP%\NSLDB6D.TMP\SHELLLINK.DLL %TEMP%\NSLDB6D.TMP\SHHELPER.DLL %TEMP%\NSLDB6D.TMP\SOCKET2.DLL %TEMP%\NSLDB6D.TMP\SYSTEM.DLL %TEMP%\NSLDB6D.TMP\TOOLTIPS.DLL Detected by UnHackMe: SOCKET2.DLL DEFAULT LOCATION: %TEMP%\NSLDB6D.TMP\SOCKET2.DLL Dropper hash(md5): 4579332fa3d69af4d40fe4da62f27d64 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does…

Continue reading

not-a-virus:RiskTool.Win32.BitCoinMiner.hxzw

not-a-virus:RiskTool.Win32.BitCoinMiner.hxzw also known as generic.a, Win32:Malware-gen. Malware Analysis of not-a-virus:RiskTool.Win32.BitCoinMiner.hxzw – IDDLEN.EXE Created files: %TEMP%\F653093198E5B5E7DD1C53AC999B4875.JSON %APPDATA%\MICROSOFT\DEVENCL.EXE %APPDATA%\MICROSOFT\IDDLEN.EXE %APPDATA%\MICROSOFT\LIBCRYPTO-1.0.0.DLL %APPDATA%\MICROSOFT\LIBCURL-4.DLL Autostart registry keys: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\DEVENCL.EXE: “%APPDATA%\MICROSOFT\DEVENCL.EXE” Detected by UnHackMe: IDDLEN.EXE DEFAULT LOCATION: %APPDATA%\MICROSOFT\IDDLEN.EXE Dropper hash(md5): afd5eb72bb8f02b9e9bbb7594e0d3cd4 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it…

Continue reading

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera