Jump to content

Malwarebytes

VirusRemover2008


1 reply to this topic

#1
SpySentinel

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 1,848 posts
  • Gender:Male
  • Location:The United States
  • Interests:Fighting/Analyzing Malware & Social Media
hxxp://www.virusremover2008.com/

Posted Image

More Info

Installation
When the program is executed, it creates the following files:

* %ProgramFiles%\VirusRemover2008\VRM2008.exe - (detected as VirusRemover2008)
* %ProgramFiles%\VirusRemover2008\Viruses.bdt - (clean file)
* %SystemDrive%\VirusRemover2008.lnk
* %SystemDrive%\Documents and Settings\Administrator\Desktop\VirusRemover2008.lnk
* %SystemDrive%\Documents and Settings\All Users\Start Menu\Programs\VirusRemover2008
* %SystemDrive%\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusRemover2008.lnk


Next, the program creates the following registry entry so that it executes whenever Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"VirusRemover2008" = "%ProgramFiles%\VirusRemover2008\VRM2008.exe"

It also creates the following registry entries:

* HKEY_LOCAL_MACHINE\SOFTWARE\VirusRemover2008\"ActivationCode" = "36"
* HKEY_LOCAL_MACHINE\SOFTWARE\VirusRemover2008\"CookieParams" = "29"
* HKEY_LOCAL_MACHINE\SOFTWARE\VirusRemover2008\"InfectionCount" = "4"
* HKEY_LOCAL_MACHINE\SOFTWARE\VirusRemover2008\"InstallDate" = "16"
* HKEY_LOCAL_MACHINE\SOFTWARE\VirusRemover2008\"LastDetectTime" = "[RANDOM HEXIDECIMAL STRING]"
* HKEY_LOCAL_MACHINE\SOFTWARE\VirusRemover2008\"LastScanTime" = "[RANDOM HEXIDECIMAL STRING]"
* HKEY_LOCAL_MACHINE\SOFTWARE\VirusRemover2008\"TotalScanCount" = "4"
* HKEY_LOCAL_MACHINE\SOFTWARE\VirusRemover2008\"UpdateEnabled" = "1"


It also creates the following registry subkeys:

* HKEY_LOCAL_MACHINE\SOFTWARE\{5222008A-DD62-49c7-A735-7BD18ECC7350}
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusRemover2008
Matt Russo
Social Media Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#2
Marty111

    New Member

  • Members
  • Pip
  • 10 posts
  • Gender:Male
  • Location:United kingdom
  • Interests:computers,games,ipod,ps3,tv
domain reported to registrar we shall see what happens :angry:
Helping take rogue sites down since 2004





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us