Rootkit.Win32.Plite.pfk
Rootkit.Win32.Plite.pfk also known as Trojan/Urelas.f, Trojan.Gen, Gen:Variant.Zusy.24258 (B). Malware Analysis of Rootkit.Win32.Plite.pfk – ORKOLOB.EXE Created files: %Temp%\gbp.ini %Temp%\zebozub.exe %Temp%\~DFA19.tmp %SysDir%\golfinfo.ini %SysDir%\orkolob.exe Autostart registry keys: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\run: “%SysDir%\orkolob.exe” Detected by UnHackMe: ORKOLOB.EXE Default location: %SYSDIR%\ORKOLOB.EXE Dropper hash(md5): 7e89d20c96cf2b8e2712b4bf566a369e UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe is 100% CLEAN,…