CONIMA.EXE - Dangerous
%TEMP%\CONIMA.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
CONIMA.EXE is known as: Mal/HckPk-A [Sophos].
MD5 of CONIMA.EXE = 57601140021039344D4A4D41CA9830AF
CONIMA.EXE size is 53248 bytes.
Full path on a computer: %WINDIR%\TEMP\CONIMA.EXE
Related Files:
%COMMONAPPDATA%\SRTSERV\[FILENAME OF THE SAMPLE #1]
%COMMONAPPDATA%\SRTSERV\SDATA.DLL
%COMMONAPPDATA%\SRTSERV\TASK.DAT
%WINDIR%\TEMP\38T22DFHB.EXE
%TEMP%\1AVS.LOG
%TEMP%\4WA3X6E21.BAT
%TEMP%\J1T5TS7.EXE
%TEMP%\MOUSEDRIVER.BAT
%WINDIR%\TEMP\QTFCYYP.EXE
%TEMP%\RJYRLU1PP.BAT
%TEMP%\TBLG5TU8S.EXE
%WINDIR%\TEMP\CONIMA.EXE
%WINDIR%\TEMP\1AVS.LOG
%WINDIR%\TEMP\CJZM7H48.EXE
%WINDIR%\TEMP\DESKTOP MANAGER.BAT
%WINDIR%\TEMP\DETOURED.DLL
%WINDIR%\TEMP\J1T5TS7.EXE
%WINDIR%\TEMP\LDERHRJR.INF
%WINDIR%\TEMP\MOUSEDRIVER.BAT
%WINDIR%\TEMP\NEWE.TMP
%WINDIR%\TEMP\NEWF.TMP
%WINDIR%\TEMP\NSL13.TMP\BRANDINGURL.DLL
%WINDIR%\TEMP\NSL13.TMP\NSDIALOGS.DLL
%WINDIR%\TEMP\NSL13.TMP\SYSTEM.DLL
%WINDIR%\TEMP\NSX11.TMP\INETC.DLL
%WINDIR%\TEMP\NSX11.TMP\INSTALLMANAGER.EXE