HOSTSERVICE.EXE - Dangerous
%WinDir%\HOSTSERVICE.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
HOSTSERVICE.EXE is known as: Mal/Behav-034 [Sophos] packed with UPX [Kaspersky Lab].
MD5 of HOSTSERVICE.EXE = 085C2BB46B1F8DBADB6D2416A0AD68D2
HOSTSERVICE.EXE size is 42496 bytes.
Full path on a computer: %WINDIR%\HOSTSERVICE.EXE
Related Files:
%ALLUSERSPROFILE%\NTUSER.POL
%TEMP%\6995.ICK
%TEMP%\260156.DLL
%TEMP%\AM_[FILENAME OF THE SAMPLE #1].EXE
%WINDIR%\HOSTSERVICE.EXE
%TEMP%\NYWHT.SYS
%TEMP%\JDFF_51814.EXE
%TEMP%\E325328T.EXE
%TEMP%\FDCSAE_51814.EXE
%TEMP%\KB122303.SVE
%PROGRAMFILES%\COMMON FILES\SYSTEM\KB524047.CPU
%TEMP%\NSQ2.TMP\INETC.DLL
%TEMP%\NSQ2.TMP\INETLOAD.DLL
%TEMP%\NSQ2.TMP\MATH.DLL
%TEMP%\NSQ2.TMP\SYSTEM.DLL
%TEMP%\NSQ2.TMP\TIME.DLL
%TEMP%\OPE20.TMP
%TEMP%\OPE21.TMP
%PROGRAMFILES%\WINRAR\ICO\TAOBAO.TBICO
%FONTSDIR%\DBR06035.TTF
%SYSTEM%\269578.EXE
%SYSTEM%\COMRES.DLL.BAK
%SYSTEM%\CONNECTING
%WINDIR%\TEMP\C.BAT