DDSSD_185435.EXE - Dangerous
DDSSD_185435.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
D_0520.EXE is known as: Trojan.Win32.Agent2 [Ikarus].
MD5 of D_0520.EXE = 3D92D11C5370EB044ED57001C9BA5FBC
D_0520.EXE size is 835039 bytes.
Full path on a computer: %TEMP%\D_0520.EXE
Related Files:
%ALLUSERSPROFILE%\NTUSER.POL
%APPDATA%\MACROMEDIA\FLASH PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#WOYO.COM\SETTINGS.SOL
%APPDATA%\MACROMEDIA\FLASH PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\SETTINGS.SOL
%TEMP%\9053.ICK
%TEMP%\DDSSD_185435.EXE
%TEMP%\FFVCD_185435.EXE
%TEMP%\NSA3.TMP\INETC.DLL
%TEMP%\NSA3.TMP\MATH.DLL
%TEMP%\NSA3.TMP\SYSTEM.DLL
%TEMP%\NSA3.TMP\TIME.DLL
%TEMP%\NSV2.TMP
%PROGRAMFILES%\WINRAR\ICO\TAOBAO.TBICO
%SYSTEM%\GROUPPOLICY\MACHINE\REGISTRY.POL
%WINDIR%\TEMP\OLD1B.TMP
%WINDIR%\TEMP\OLD1F.TMP
%WINDIR%\TEMP\OLD23.TMP
%WINDIR%\TEMP\OLD27.TMP
%WINDIR%\TEMP\OLD2B.TMP
%WINDIR%\TEMP\OLD2F.TMP
%WINDIR%\TEMP\C.BAT