WINXGRDO.EXE - Dangerous
%TEMP%\WINXGRDO.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
WINMMTPFX.EXE is known as: Hacktool.Proxy [PCTools] Hacktool.Proxy [Symantec] Backdoor.Win32.Mazben.fl [Kaspersky Lab] Mal/TinyDL-T [Sophos] Virus.Win32.Sality [Ikarus] packed with UPX [Kaspersky Lab].
MD5 of WINMMTPFX.EXE = 279AD01BF1EE23661D196106784573E7
WINMMTPFX.EXE size is 12970 bytes.
Full path on a computer: %TEMP%\WINMMTPFX.EXE
Related Files:
C:\AUTORUN.INF
%TEMP%\1AVS.LOG
%TEMP%\MOUSEDRIVER.BAT
%TEMP%\PIWPJSZON.BAT
%WINDIR%\TEMP\QTFCYYP.EXE
%TEMP%\URRQTJEJ4.EXE
%TEMP%\VN1UOX5TS.BAT
%TEMP%\WINXGRDO.EXE
%WINDIR%\TEMP\ZLY0I.EXE
C:\VMDIR.EXE
%SYSTEM%\NWSAPAGENTS.DLL
%WINDIR%\TEMP\1AVS.LOG
%WINDIR%\TEMP\36WRWHQP0.EXE
%WINDIR%\TEMP\IS9ASY7Q4.EXE
%WINDIR%\TEMP\MANAGEE.EXE
%WINDIR%\TEMP\MLOG
%WINDIR%\TEMP\MOUSEDRIVER.BAT
%WINDIR%\TEMP\PLUG.BAT
%WINDIR%\TEMP\QAL8CPVOA.EXE