Archive for February, 2009
Sunday, February 8th, 2009
This is an harmful program.
Name: gaopdxqltiqmuy
Filename: gaopdxqltiqmuy.sys
Command: c:\windows\system32\drivers\gaopdxqltiqmuy.sys
Startup Type: Hidden driver
Description: Rootkit/trojan component
How to remove: How to remove trojan TDSSserv (TDSSserv.sys), clbdriver.sys and seneka.sys
Posted in Driver, Rootkit | No Comments »
Sunday, February 8th, 2009
This is an harmful program.
Name: boot
Filename: boot.com
Command: c:\resycled\boot.com
Startup Type: autorun.inf
Description: autorun.inf trojan component
How to remove: How to remove trojans that uses autorun.inf file
Posted in autorun.inf, Trojan | No Comments »
Sunday, February 8th, 2009
This is an harmful program.
Name: wjfvju
Startup Type:svchost
Combofix/RSIT Line:
R4 wjfvju;wjfvju;c:\windows\system32\SVCHOST.EXE -k wjfvju [2004-08-18 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
wjfvju REG_MULTI_SZ wjfvju
Description: unknown malware component
Posted in Malware, SvcHost | No Comments »
Sunday, February 8th, 2009
This is an harmful program.
Name: WinHelp3x
Filename: WinHelp3x.exe
Command: c:\windows\system32\WinHelp3x.exe
Startup Type: Service
Combofix/ RSIT Line:
R4 WinHelp3x;Windows Help System;c:\windows\system32\WinHelp3x.exe [2009-01-16 15910]
Description: unknown trojan component
Posted in Malware, Service | No Comments »
Monday, February 2nd, 2009
This is an harmful program.
Name: WinHelp31
Filename: WinHelp31.exe
Command: c:\windows\system32\WinHelp31.exe
Startup Type: Service
RSIT/Combofix Line:
R4 WinHelp31;Windows Help System1;c:\windows\system32\WinHelp31.exe [2009-01-16 41217]
Description: unknown malware
Posted in Malware, Service | No Comments »
Monday, February 2nd, 2009
This is an harmful program.
Name: SafeTest
Filename: SafeTest.exe
Registry key:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SafeTest”=”c:\windows\system32\SafeTest.exe” [2009-01-16 69484]
Command: c:\windows\system32\SafeTest.exe
Startup Type: HKLM->Run
HijackThis Category: O4
Description: unknown malware
Posted in Malware, O4, Run | No Comments »
Monday, February 2nd, 2009
This is an harmful program.
Name: S002
Filename: S002.exe
Command: C:\WINDOWS\system32\oaVWe\S002.exe
Startup Type: Service
RSIT/Combofix Line:
S2 RemoteStorages;Network Connections Management; C:\WINDOWS\system32\oaVWe\S002.exe [2009-01-19 43008]
Description: unknown malware
Posted in Malware, Service | No Comments »
Monday, February 2nd, 2009
This is an harmful program.
Name: DuBa
Filename: DuBa.exe
Command: C:\WINDOWS\system32\DuBa.exe
Startup Type: Service
RSIT/Combofix Line:
S2 KingDuuBa;KingDuBa Driver; C:\WINDOWS\system32\DuBa.exe [2009-01-19 304640]
Description: unknown malware
Notes:
Posted in Malware, Service | No Comments »
Monday, February 2nd, 2009
This is an harmful program.
Name: jgok
Filename: jgok.exe
Command: C:\WINDOWS\system32\jgok.exe
Startup Type: Service
RSIT/Combofix Line:
Description: unknown malware
Posted in Malware, Service | No Comments »
Monday, February 2nd, 2009
This is an harmful program.
Name: reat
Filename: reat.exe
Command: C:\Program Files\reat.exe
Startup Type: Service
RSIT/Combofix Line:
S2 Brewser;Compvter Brewser; C:\Program Files\reat.exe [2008-10-01 718336]
Description: Unknown malware
Posted in Malware, Service | No Comments »