HSTART.EXE - Dangerous
%WinDir%\HSTART.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
HSTART.EXE is known as: Trojan.Crypt [Ikarus].
MD5 of HSTART.EXE = 228DAFB19878532CB1B2C474BA5DF7D3
HSTART.EXE size is 16896 bytes.
Full path on a computer: %WINDIR%\HSTART.EXE
Related Files:
C:\BT\BT.LNK
C:\BT\DISABLE\BT.CMD
C:\BT\ENABLE\BT.CMD
%TEMP%\1.TMP\CHECKOS.TXT
%TEMP%\1.TMP\STRINGCHECK.TXT
%TEMP%\1.TMP\X64.EXE
%TEMP%\1.TMP\X86.EXE
%PROGRAMFILES%\LAUNCH MANAGER\5920BT.EXE
%PROGRAMFILES%\LAUNCH MANAGER\BLUETOOTHCFG.EXE
%PROGRAMFILES%\LAUNCH MANAGER\BT.EXE
%PROGRAMFILES%\LAUNCH MANAGER\INSTALL.BAT
%PROGRAMFILES%\LAUNCH MANAGER\INSTALL.EXE
%PROGRAMFILES%\LAUNCH MANAGER\LMANAGER.EXE
%PROGRAMFILES%\LAUNCH MANAGER\MMKEYBD.CFG
%PROGRAMFILES%\LAUNCH MANAGER\MMKEYBDBT.CFG
%PROGRAMFILES%\LAUNCH MANAGER\PANEL\LMANAGER.ICO
%PROGRAMFILES%\LAUNCH MANAGER\POWERTOGGLE.EXE
%PROGRAMFILES%\LAUNCH MANAGER\RELEASE.TXT
%PROGRAMFILES%\LAUNCH MANAGER\SETTINGS.REG
%PROGRAMFILES%\LAUNCH MANAGER\SYNTPSCROLLFIX.EXE
%PROGRAMFILES%\LAUNCH MANAGER\WHQL_LH\DKBFLTR.SYS
%PROGRAMFILES%\LAUNCH MANAGER\WHQL_LH\LMANAGER.CAT
%PROGRAMFILES%\LAUNCH MANAGER\WHQL_LH\LMANAGER.INF
%WINDIR%\DEVCON.EXE
%WINDIR%\HSTART.EXE
%WINDIR%\NIRCMD.EXE
%WINDIR%\NIRCMDC.EXE