Dmitry Sokolov recommends UnHackMe!
UnHackMe is a powerful tool against malware.UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!
Win32.Trojan.Falsesign.Wtdp also known as not-a-virus:HEUR:WebToolbar.Win32.Agent.gen, HEUR/QVM20.1.Malware.Gen.
Malware Analysis of Win32.Trojan.Falsesign.Wtdp – T8MEDINT.EXE
Created files:
%Program Files%\PremierDownloadManager\pdmanager_ie.tlb
%Program Files%\PremierDownloadManager\RegAsm.exe
%Program Files%\PremierDownloadManager\t8MedInt.exe
%Program Files%\PremierDownloadManager\TooltabExtension.dll
%Program Files%\PremierDownloadManager\TooltabExtension.ini
Autostart registry keys:
HKLM\Software\Classes\CLSID\{819D045F-E9A2-39E0-B495-D615AD1A9471}\InprocServer32\: “mscoree.dll”
HKLM\Software\Classes\CLSID\{87D1BD5F-0174-4AB2-FFC4-9E3A451F17EB}\InprocServer32\: “mscoree.dll”
HKLM\Software\Classes\CLSID\{DA024AE8-AE02-4D90-ACCA-573716C04C39}\InprocServer32\: “%Program Files%\PremierDownloadManager\TooltabExtension.dll”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark PremierDownloadManager\DisplayName: “Premier Download Manager”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark PremierDownloadManager\UninstallString: “”%Program Files%\PremierDownloadManager\\UninstallSF.exe” “/U:%Program Files%\PremierDownloadManager\Uninstall\uninstall.xml””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Premier Download Manager\DisplayName: “”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Premier Download Manager\UninstallString: “%Program Files%\PremierDownloadManager\uninstall.exe”
Detected by UnHackMe:
T8MEDINT.EXE
Default location: %PROGRAM FILES%\PREMIERDOWNLOADMANAGER\T8MEDINT.EXE
Dropper hash(md5): 524243b67ca1dc5aeba6648306ef0593
UnHackMe
removes malware invisible for your antivirus!
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.