XCMD.EXE - Dangerous
%TEMP%\XCMD.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
XCMD.EXE is known as: packed with UPX [Kaspersky Lab].
MD5 of XCMD.EXE = 378E0103156F2E6844C83087D80A7156
XCMD.EXE size is 33280 bytes.
Full path on a computer: %TEMP%\XCMD.EXE
Related Files:
C:\CCPMACHINEINFO.DLL
%COMMONDESKTOPDIR%\INTERNAT EXPLORER.RNK57
%PROGRAMFILES%\NETMEETING\IE.HTML
%DESKTOPDIR%\COOPEN.LNK
%DESKTOPDIR%\ﯽԱﯽﯽﯽ.ﯽأﯽ.TEP
%DESKTOPDIR%\À¡ï¯½ï¯½Ï·.TEP
%FAVORITES%\ﯽԱﯽﯽﯽ.URL
%FAVORITES%\À¡ï¯½ï¯½Ï·.URL
%TEMP%\COOPEN_SETUP_100030.EXE
%TEMP%\NSJ3.TMP\REGISTRY.DLL
%TEMP%\XCMD.EXE
%PROGRAMFILES%\COOPEN\COOPEN.EXE
%SYSTEM%\COOPEN.SCR
%PROGRAMFILES%\COOPEN\COOPENACTIVECONTROL110.DLL
%PROGRAMFILES%\COOPEN\COOPENAIR.EXE
%PROGRAMFILES%\COOPEN\COOPENMAINMANAGER.DLL