Category Archives: Rootkit

RootKit.Win32.Fednu.w

RootKit.Win32.Fednu.w also known as W32/Koutodoor.A!tr.rkit, RTKT_KTDOOR.SMIB. Malware Analysis of RootKit.Win32.Fednu.w – VIWE.SYS Created files: %Temp%\jatjoxn.bat %Temp%\jqapbk.exe %SysDir%\drivers\viwe.sys %SysDir%\xscf.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\viw\ImagePath: “system32\drivers\viwe.sys” HKLM\System\CurrentControlSet\Services\viw\DisplayName: “viw” Detected by UnHackMe: VIWE.SYS Default location: %SYSDIR%\DRIVERS\VIWE.SYS Dropper hash(md5): d851ec5f3870a751c6442f9561892c92 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means…

Continue reading

Rootkit.Win32.Vanti.ep

Rootkit.Win32.Vanti.ep also known as Trojan/Vanti.ep, Trojan.MulDrop.4378, Packer.Malware.NSAnti.D. Malware Analysis of Rootkit.Win32.Vanti.ep – Z.DLL Created files: %Temp%\z.dll %SysDir%\xydll.dll %WinDir%\Download\svhost32.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\xy: “%WinDir%\Download\svhost32.exe” Detected by UnHackMe: Z.DLL Default location: %TEMP%\Z.DLL Dropper hash(md5): d876c4a74824ad7d9e823db501654570 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does…

Continue reading

Rootkit.Win32.Vanti.df

Rootkit.Win32.Vanti.df also known as VirTool:Win32/Vanti.gen!D, NSAnti.TZK, Trojan.Win32.Amvo.Gen. Malware Analysis of Rootkit.Win32.Vanti.df – Z.DLL Created files: %Temp%\z.dll %SysDir%\xydll.dll %WinDir%\Download\svhost32.exe Autostart registry keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\xy: “%WinDir%\Download\svhost32.exe” Detected by UnHackMe: Z.DLL Default location: %TEMP%\Z.DLL Dropper hash(md5): d876c4a74824ad7d9e823db501654570 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does…

Continue reading

Rootkit.Agent.kui

Rootkit.Agent.kui also known as Gen:Variant.Jadtre.1, TROJ_AGENT.BDGE, W32/Rootkit.N.gen!Eldorado. Malware Analysis of Rootkit.Agent.kui – 5A8677BD.SYS Created files: %Temp%\BIT4.tmp C:\Documents and Settings\NetworkService\Favorites\Desktop.ini %SysDir%\5A8677BD.sys %SysDir%\dmlocalsvc.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\5A8677BD\ImagePath: “system32\5A8677BD.sys” Detected by UnHackMe: 5A8677BD.SYS Default location: %SYSDIR%\5A8677BD.SYS Dropper hash(md5): d6656e4c4270aa1ee241ef9530c8d680 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which…

Continue reading

Rootkit.37308

Rootkit.37308 also known as Win32:Rootkit-gen, Rootkit.Win32.Agent.bhvc, W32/Suspicious_Gen2.BEHZZ. Malware Analysis of Rootkit.37308 – 73094446.SYS Created files: %SysDir%\drivers\73094446.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\73094446\ImagePath: “system32\drivers\73094446.sys” Detected by UnHackMe: 73094446.SYS Default location: %SYSDIR%\DRIVERS\73094446.SYS Dropper hash(md5): d6568b99cc7271781304880b1a11dcd0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain…

Continue reading

Rootkit.Win32.Agent.bhvc

Rootkit.Win32.Agent.bhvc also known as W32/Agent.BHVC!tr.rkit, VirTool:WinNT/Jadtre.B, Win32/Wapomi.D. Malware Analysis of Rootkit.Win32.Agent.bhvc – 73094446.SYS Created files: %SysDir%\drivers\73094446.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\73094446\ImagePath: “system32\drivers\73094446.sys” Detected by UnHackMe: 73094446.SYS Default location: %SYSDIR%\DRIVERS\73094446.SYS Dropper hash(md5): d6568b99cc7271781304880b1a11dcd0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain…

Continue reading

Win32.Rootkit

Win32.Rootkit also known as VirTool.WinNT.Jadtre, Riskware.WinNT.Jadtre!IK, Rootkit.37308. Malware Analysis of Win32.Rootkit – 73094446.SYS Created files: %SysDir%\drivers\73094446.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\73094446\ImagePath: “system32\drivers\73094446.sys” Detected by UnHackMe: 73094446.SYS Default location: %SYSDIR%\DRIVERS\73094446.SYS Dropper hash(md5): d6568b99cc7271781304880b1a11dcd0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain…

Continue reading

Rootkit.Win32.Agent.bhta

Rootkit.Win32.Agent.bhta also known as Trj/Downloader.MDW, Dropper.Generic2.TYW, Trojan.Win32.Generic!BT. Malware Analysis of Rootkit.Win32.Agent.bhta – 73094446.SYS Created files: %SysDir%\drivers\73094446.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\73094446\ImagePath: “system32\drivers\73094446.sys” Detected by UnHackMe: 73094446.SYS Default location: %SYSDIR%\DRIVERS\73094446.SYS Dropper hash(md5): d6568b99cc7271781304880b1a11dcd0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain…

Continue reading

Rootkit.W32.Agent.dgih!c

Rootkit.W32.Agent.dgih!c also known as Trojan[Rootkit]/Win32.Agent, Riskware ( 0015e4f01 ), a variant of Win32/Wapomi.AC. Malware Analysis of Rootkit.W32.Agent.dgih!c – 5A8677BD.SYS Created files: %Temp%\BIT4.tmp C:\Documents and Settings\NetworkService\Favorites\Desktop.ini %SysDir%\5A8677BD.sys %SysDir%\dmlocalsvc.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\5A8677BD\ImagePath: “system32\5A8677BD.sys” Detected by UnHackMe: 5A8677BD.SYS Default location: %SYSDIR%\5A8677BD.SYS Dropper hash(md5): d6656e4c4270aa1ee241ef9530c8d680 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus…

Continue reading

RootKit.Win32.Fednu.k

RootKit.Win32.Fednu.k also known as Riskware.WinNT.Jadtre!IK, Rootkit.Win32.Agent.bhvc, Generic.dx!taj. Malware Analysis of RootKit.Win32.Fednu.k – 73094446.SYS Created files: %SysDir%\drivers\73094446.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\73094446\ImagePath: “system32\drivers\73094446.sys” Detected by UnHackMe: 73094446.SYS Default location: %SYSDIR%\DRIVERS\73094446.SYS Dropper hash(md5): d6568b99cc7271781304880b1a11dcd0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain…

Continue reading

Rootkit.W32.Agent.bird!c

Rootkit.W32.Agent.bird!c also known as TR/Rootkit.Gen, Gen:Variant.Jadtre.1, Rootkit.Agent. Malware Analysis of Rootkit.W32.Agent.bird!c – 31FE0EE3.SYS Created files: %Temp%\BIT3.tmp %SysDir%\31FE0EE3.sys %SysDir%\dmutilio.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\31FE0EE3\ImagePath: “system32\31FE0EE3.sys” Detected by UnHackMe: 31FE0EE3.SYS Default location: %SYSDIR%\31FE0EE3.SYS Dropper hash(md5): d6465d28f1a5080eeb4ed276835aa0a0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does…

Continue reading

Rootkit.W32.Agent.bivy!c

Rootkit.W32.Agent.bivy!c also known as Win32/Wapomi.U, W32/Agent.SDT!tr.rkit, Trojan.Win32.Generic!BT. Malware Analysis of Rootkit.W32.Agent.bivy!c – 2C87517D.SYS Created files: %Temp%\BIT3.tmp %SysDir%\2C87517D.sys %SysDir%\dmutilio.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\2C87517D\ImagePath: “system32\2C87517D.sys” Detected by UnHackMe: 2C87517D.SYS Default location: %SYSDIR%\2C87517D.SYS Dropper hash(md5): d6286aad661216c22b4f53494434dc90 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does…

Continue reading

Rootkit.Agent.Win32.9413

Rootkit.Agent.Win32.9413 also known as Rootkit.Agent, Mal/Rootkit-Z, Trojan.Win32.Generic!BT. Malware Analysis of Rootkit.Agent.Win32.9413 – 2C87517D.SYS Created files: %Temp%\BIT3.tmp %SysDir%\2C87517D.sys %SysDir%\dmutilio.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\2C87517D\ImagePath: “system32\2C87517D.sys” Detected by UnHackMe: 2C87517D.SYS Default location: %SYSDIR%\2C87517D.SYS Dropper hash(md5): d6286aad661216c22b4f53494434dc90 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does…

Continue reading

RootKit.Win32.Ressdt.A

RootKit.Win32.Ressdt.A also known as Win32/Wapomi.F, W32/Rootkit.N.gen!Eldorado, TR/Rootkit.Gen. Malware Analysis of RootKit.Win32.Ressdt.A – 2172036C.SYS Created files: %SysDir%\drivers\2172036C.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\2172036C\ImagePath: “system32\drivers\2172036C.sys” Detected by UnHackMe: 2172036C.SYS Default location: %SYSDIR%\DRIVERS\2172036C.SYS Dropper hash(md5): d6261de9e53ad25c4150e6de41e61a70 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain…

Continue reading

Rootkit.W32.Agent.bhzo!c

Rootkit.W32.Agent.bhzo!c also known as Gen:Variant.Jadtre.1, Rootkit.Agent.r5, W32/Rootkit.N.gen!Eldorado. Malware Analysis of Rootkit.W32.Agent.bhzo!c – 2172036C.SYS Created files: %SysDir%\drivers\2172036C.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\2172036C\ImagePath: “system32\drivers\2172036C.sys” Detected by UnHackMe: 2172036C.SYS Default location: %SYSDIR%\DRIVERS\2172036C.SYS Dropper hash(md5): d6261de9e53ad25c4150e6de41e61a70 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain…

Continue reading

Rootkit.Agent.Win32.7898

Rootkit.Agent.Win32.7898 also known as Gen:Variant.Jadtre.1, Rootkit.Agent!eZ7SoBn3Ti4, Trojan.Win32.Generic!BT. Malware Analysis of Rootkit.Agent.Win32.7898 – 2172036C.SYS Created files: %SysDir%\drivers\2172036C.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\2172036C\ImagePath: “system32\drivers\2172036C.sys” Detected by UnHackMe: 2172036C.SYS Default location: %SYSDIR%\DRIVERS\2172036C.SYS Dropper hash(md5): d6261de9e53ad25c4150e6de41e61a70 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain…

Continue reading

Rootkit.Agent.hoq

Rootkit.Agent.hoq also known as Trojan ( 0017df6e1 ), RootKit.Win32.Ressdt.A, Trojan.Win32.RootKit.aem. Malware Analysis of Rootkit.Agent.hoq – 2172036C.SYS Created files: %SysDir%\drivers\2172036C.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\2172036C\ImagePath: “system32\drivers\2172036C.sys” Detected by UnHackMe: 2172036C.SYS Default location: %SYSDIR%\DRIVERS\2172036C.SYS Dropper hash(md5): d6261de9e53ad25c4150e6de41e61a70 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it…

Continue reading

Rootkit.Agent.hzr

Rootkit.Agent.hzr also known as Gen:Variant.Jadtre.1, BehavesLike.Win32.Simfect.xh, VirTool.WinNT.Jadtre. Malware Analysis of Rootkit.Agent.hzr – 04DA3E1F.SYS Created files: %SysDir%\04DA3E1F.sys %SysDir%\dmutilio.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\04DA3E1F\ImagePath: “system32\04DA3E1F.sys” Detected by UnHackMe: 04DA3E1F.SYS Default location: %SYSDIR%\04DA3E1F.SYS Dropper hash(md5): d7651a41b149d61475dc2c894810ecac UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not…

Continue reading

Rootkit.W32.Agent.dgsa!c

Rootkit.W32.Agent.dgsa!c also known as Gen:Variant.Jadtre.1, Trojan:Win32/Dorv.C!rfn. Malware Analysis of Rootkit.W32.Agent.dgsa!c – 04DA3E1F.SYS Created files: %SysDir%\04DA3E1F.sys %SysDir%\dmutilio.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\04DA3E1F\ImagePath: “system32\04DA3E1F.sys” Detected by UnHackMe: 04DA3E1F.SYS Default location: %SYSDIR%\04DA3E1F.SYS Dropper hash(md5): d7651a41b149d61475dc2c894810ecac UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not contain…

Continue reading

Rootkit.Agent.Win32.7962

Rootkit.Agent.Win32.7962 also known as Gen:Variant.Jadtre.1, Generic Malware, Trojan ( 0019e59f1 ). Malware Analysis of Rootkit.Agent.Win32.7962 – 04DA3E1F.SYS Created files: %SysDir%\04DA3E1F.sys %SysDir%\dmutilio.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\04DA3E1F\ImagePath: “system32\04DA3E1F.sys” Detected by UnHackMe: 04DA3E1F.SYS Default location: %SYSDIR%\04DA3E1F.SYS Dropper hash(md5): d7651a41b149d61475dc2c894810ecac UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which…

Continue reading

Rootkit.Agent.Win32.7983

Rootkit.Agent.Win32.7983 also known as Trojan.Win32.Agent.dwvep, Rootkit/KillAV.NM, Trojan/W32.Small.8736.B. Malware Analysis of Rootkit.Agent.Win32.7983 – 11CE6DCD.SYS Created files: %SysDir%\11CE6DCD.sys %SysDir%\dmutilio.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\11CE6DCD\ImagePath: “system32\11CE6DCD.sys” Detected by UnHackMe: 11CE6DCD.SYS Default location: %SYSDIR%\11CE6DCD.SYS Dropper hash(md5): d7995de65a6a9ad1459ad8d266326ff0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it does not…

Continue reading

Rootkit.W32.Agent.biqn!c

Rootkit.W32.Agent.biqn!c also known as Trojan.Win32.Generic!BT, Win32:Jadtre-H [Rtk], PE:Malware.Generic/QRS!1.9E2D [F]. Malware Analysis of Rootkit.W32.Agent.biqn!c – 11CE6DCD.SYS Created files: %SysDir%\11CE6DCD.sys %SysDir%\dmutilio.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\11CE6DCD\ImagePath: “system32\11CE6DCD.sys” Detected by UnHackMe: 11CE6DCD.SYS Default location: %SYSDIR%\11CE6DCD.SYS Dropper hash(md5): d7995de65a6a9ad1459ad8d266326ff0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it…

Continue reading

Rootkit.Agent.ich

Rootkit.Agent.ich also known as Trojan ( 0019a1d11 ), W32/Rootkit.N.gen!Eldorado, Rootkit/KillAV.NM. Malware Analysis of Rootkit.Agent.ich – 11CE6DCD.SYS Created files: %SysDir%\11CE6DCD.sys %SysDir%\dmutilio.dll Autostart registry keys: HKLM\System\CurrentControlSet\Services\11CE6DCD\ImagePath: “system32\11CE6DCD.sys” Detected by UnHackMe: 11CE6DCD.SYS Default location: %SYSDIR%\11CE6DCD.SYS Dropper hash(md5): d7995de65a6a9ad1459ad8d266326ff0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means…

Continue reading

Win32/RootKit.Rootkit.5ec

Win32/RootKit.Rootkit.5ec also known as Rootkit.Agent/Gen-SysX, VirTool:WinNT/Jadtre.gen, Trojan.Generic.7646619. Malware Analysis of Win32/RootKit.Rootkit.5ec – 692B1948.SYS Created files: %SysDir%\drivers\692B1948.sys %SysDir%\142A65A7.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\142A65A7\ImagePath: “\??\%SysDir%\142A65A7.sys” HKLM\System\CurrentControlSet\Services\142A65A7\DisplayName: “142A65A7” Detected by UnHackMe: 692B1948.SYS Default location: %SYSDIR%\DRIVERS\692B1948.SYS Dropper hash(md5): d7858ea0b663289d5f1ac62c1d4233e0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it…

Continue reading

Rootkit.W32.Agent.dgcg!c

Rootkit.W32.Agent.dgcg!c also known as W32.Clod1a0.Trojan.5fa3, W32/Rootkit.N.gen!Eldorado, Artemis!CC488EE75AD6. Malware Analysis of Rootkit.W32.Agent.dgcg!c – 142A65A7.SYS Created files: %SysDir%\drivers\692B1948.sys %SysDir%\142A65A7.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\142A65A7\ImagePath: “\??\%SysDir%\142A65A7.sys” HKLM\System\CurrentControlSet\Services\142A65A7\DisplayName: “142A65A7” Detected by UnHackMe: 142A65A7.SYS Default location: %SYSDIR%\142A65A7.SYS Dropper hash(md5): d7858ea0b663289d5f1ac62c1d4233e0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it…

Continue reading

Rootkit.W32.Agent.bhqg!c

Rootkit.W32.Agent.bhqg!c also known as Rootkit.Agent.Win32.7891, Dropper.Generic2.SEV, Trojan.Generic.7646619. Malware Analysis of Rootkit.W32.Agent.bhqg!c – 692B1948.SYS Created files: %SysDir%\drivers\692B1948.sys %SysDir%\142A65A7.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\142A65A7\ImagePath: “\??\%SysDir%\142A65A7.sys” HKLM\System\CurrentControlSet\Services\142A65A7\DisplayName: “142A65A7” Detected by UnHackMe: 692B1948.SYS Default location: %SYSDIR%\DRIVERS\692B1948.SYS Dropper hash(md5): d7858ea0b663289d5f1ac62c1d4233e0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it…

Continue reading

Rootkit.Agent.hme

Rootkit.Agent.hme also known as Rootkit.Agent.Win32.7891, RTKT_JADTRE.SMA, HEUR:Trojan.Win32.Generic. Malware Analysis of Rootkit.Agent.hme – 692B1948.SYS Created files: %SysDir%\drivers\692B1948.sys %SysDir%\142A65A7.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\142A65A7\ImagePath: “\??\%SysDir%\142A65A7.sys” HKLM\System\CurrentControlSet\Services\142A65A7\DisplayName: “142A65A7” Detected by UnHackMe: 692B1948.SYS Default location: %SYSDIR%\DRIVERS\692B1948.SYS Dropper hash(md5): d7858ea0b663289d5f1ac62c1d4233e0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN, which means it…

Continue reading

BScope.Rootkit-Dropper.TDSL.hm

BScope.Rootkit-Dropper.TDSL.hm also known as PUP.Optional.YesSearches. Malware Analysis of BScope.Rootkit-Dropper.TDSL.hm – AROGEGH.EXE Created files: %Program Files%\PC Speed Up\unins000.exe %Program Files%\PC Speed Up\unins000.msg %Program Files%\yesbnd\arogegh.exe %Program Files%\yesbnd\CCeuter.exe %Program Files%\yesbnd\conf.json Autostart registry keys: HKLM\System\CurrentControlSet\Services\PCSUService\ImagePath: “%Program Files%\PC Speed Up\PCSUService.exe” HKLM\System\CurrentControlSet\Services\PCSUService\DisplayName: “PC Speed Up Service” Detected by UnHackMe: AROGEGH.EXE Default location: %PROGRAM FILES%\YESBND\AROGEGH.EXE Dropper hash(md5): cba06fb06ea1606b0c2ec29befa5d77d UnHackMe removes malware invisible…

Continue reading

Win32.Rootkit.Agent.x

Win32.Rootkit.Agent.x also known as Trojan[Rootkit]/Win32.Agent, Mal/Rootkit-Z, Trojan ( 000170b31 ). Malware Analysis of Win32.Rootkit.Agent.x – 142A65A7.SYS Created files: %SysDir%\drivers\692B1948.sys %SysDir%\142A65A7.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\142A65A7\ImagePath: “\??\%SysDir%\142A65A7.sys” HKLM\System\CurrentControlSet\Services\142A65A7\DisplayName: “142A65A7” Detected by UnHackMe: 142A65A7.SYS Default location: %SYSDIR%\142A65A7.SYS Dropper hash(md5): d7858ea0b663289d5f1ac62c1d4233e0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN,…

Continue reading

Win32/RootKit.Rootkit.907

Win32/RootKit.Rootkit.907 also known as Gen:Variant.Jadtre.1, Trojan.Win32.Guntior2.reno, Trojan ( 000170b31 ). Malware Analysis of Win32/RootKit.Rootkit.907 – 142A65A7.SYS Created files: %SysDir%\drivers\692B1948.sys %SysDir%\142A65A7.sys Autostart registry keys: HKLM\System\CurrentControlSet\Services\142A65A7\ImagePath: “\??\%SysDir%\142A65A7.sys” HKLM\System\CurrentControlSet\Services\142A65A7\DisplayName: “142A65A7” Detected by UnHackMe: 142A65A7.SYS Default location: %SYSDIR%\142A65A7.SYS Dropper hash(md5): d7858ea0b663289d5f1ac62c1d4233e0 UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN,…

Continue reading

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera