CRYPTED FILE.EXE - Dangerous
CRYPTED FILE.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
CRYPTED FILE.EXE is known as: Backdoor.Win32.Poison.apdo [Kaspersky Lab] Generic Dropper.hr [McAfee] Troj/VB-EHM [Sophos] TrojanDropper:Win32/VB.HM [Microsoft] Trojan-Dropper.Win32.VB [Ikarus] Dropper/Xema.20480.EI [AhnLab].
MD5 of CRYPTED FILE.EXE = 8F540F5A6F57E4B0B1F4F24AEFD7D5E6
CRYPTED FILE.EXE size is 29702 bytes.
Full path on a computer: %WINDIR%\CRYPTED FILE.EXE
Related Files:
%TEMP%\MSN.EXE
%PROGRAMFILES%\CRAKALL\CRESTRA 1.0\CRESTRA 1.0-WWW.DESCARGASHACK.COM\CLIENT.EXE
%PROGRAMFILES%\CRAKALL\CRESTRA 1.0\CRESTRA 1.0-WWW.DESCARGASHACK.COM\ICONRES.DLL
%PROGRAMFILES%\CRAKALL\CRESTRA 1.0\CRESTRA 1.0-WWW.DESCARGASHACK.COM\LEEME.TXT
%PROGRAMFILES%\CRAKALL\CRESTRA 1.0\CRESTRA 1.0-WWW.DESCARGASHACK.COM\PLUGINS\KAVFUK.DLL
%PROGRAMFILES%\CRAKALL\CRESTRA 1.0\CRESTRA 1.0-WWW.DESCARGASHACK.COM\PLUGINS\KERNELUNHOOKING.DLL
%PROGRAMFILES%\CRAKALL\CRESTRA 1.0\CRESTRA 1.0-WWW.DESCARGASHACK.COM\PLUGINS\USERMODEUNHOOKING.DLL
%PROGRAMFILES%\CRAKALL\CRESTRA 1.0\CRESTRA 1.0-WWW.DESCARGASHACK.COM\PROJECT.EXE
%PROGRAMFILES%\CRAKALL\CRESTRA 1.0\CRESTRA 1.0-WWW.DESCARGASHACK.COM\WWW.DESCARGASHACK.COM.URL
%PROGRAMFILES%\CRAKALL\CRESTRA 1.0\UNINSTALL.EXE
%PROGRAMFILES%\CRAKALL\CRESTRA 1.0\UNINSTALL.INI
%WINDIR%\CRYPTED FILE.EXE