Archive for the 'Worm' Category
Tuesday, December 8th, 2009
mstre25.exe is a harmful program.
Name: mstre25
Filename: mstre25.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | SySmstray
Command: C:\windows\mstre25.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [SySmstray] C:\windows\mstre25.exe
DDS Line:
mRun: [SySmstray] C:\windows\mstre25.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“SySmstray”=c:\windows\mstre25.exe
Description: component of Koobface worm.
How to remove: use these Koobface removal instructions.
Posted in O4, Run, Worm | No Comments »
Sunday, November 22nd, 2009
mstre24.exe is a harmful program.
Name: mstre24
Filename: mstre24.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | SySmstray
Command: C:\windows\mstre24.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [SySmstray] C:\windows\mstre24.exe
DDS Line:
mRun: [SySmstray] c:\windows\mstre24.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“SySmstray”=c:\windows\mstre24.exe
Description: component of Koobface worm
How to remove: use HijackThis + Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Thursday, November 19th, 2009
freddy75.exe is a harmful program.
Name: freddy75
Filename: freddy75.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysfbtray
Command: C:\windows\freddy75.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sysfbtray] C:\windows\freddy75.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysfbtray”=C:\windows\freddy75.exe
Description: component of Koobface worm.
How to remove: use these Koobface removal instructions.
Posted in O4, Run, Worm | 2 Comments »
Tuesday, November 17th, 2009
freddy74.exe is a harmful program.
Name: freddy74
Filename: freddy74.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysfbtray
Command: C:\windows\freddy74.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sysfbtray] C:\windows\freddy74.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysfbtray”=C:\windows\freddy74.exe
Description: part of Koobface worm
How to remove: use HijackThis +Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Wednesday, November 11th, 2009
mstre22.exe is a harmful program.
Name: mstre22
Filename: mstre22.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | SySmstray
Command: C:\Windows\mstre22.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [SySmstray] C:\Windows\mstre22.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“SySmstray”=C:\Windows\mstre22.exe
Description: part of Koobface worm
How to remove: use HijackThis + Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Wednesday, October 28th, 2009
freddy72.exe is a harmful program.
Name: freddy72
Filename: freddy72.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysfbtray
Command: C:\windows\freddy72.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sysfbtray] C:\windows\freddy71.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysfbtray”=C:\windows\freddy72.exe [2009-10-27 73,728]
Description: component of koobface worm
How to remove: use HijackThis and Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Friday, October 23rd, 2009
freddy71.exe is a harmful program.
Name: freddy71
Filename: freddy71.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysfbtray
Command: C:\windows\freddy71.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sysfbtray] C:\windows\freddy71.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysfbtray”=C:\windows\freddy71.exe [2009-10-20 55296]
Description: part of koobface worm
How to remove: use HijackThis + use Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Friday, October 23rd, 2009
ld15.exe is a harmful program.
Name: ld15
Filename: ld15.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysldtray
Command: C:\windows\ld15.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sysldtray] C:\windows\ld15.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysldtray”=C:\windows\ld15.exe [2009-10-20 38912]
Description: part of worm koobface
How to remove: use HijackThis + use Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Tuesday, September 29th, 2009
This is a harmful program.
Name: ld14
Filename: ld14.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysldtray
Command: C:\Windows\ld14.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sysldtray] C:\Windows\ld14.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysldtray”=C:\Windows\ld14.exe [2009-09-23 61440]
Description: component of worm koobface, that takes over computers by spreading through the social networks
How to remove: use Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Tuesday, September 29th, 2009
This is a harmful program.
Name: pp12
Filename: pp12.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | pp
Command: C:\Windows\pp12.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [pp] C:\Windows\pp12.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“pp”=C:\Windows\pp12.exe [2009-09-23 49152]
Description: component of worm koobface
How to remove: use Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »