GETHASHES.EXE - Dangerous
GETHASHES.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
GETHASHES.EXE is known as: SecurityRisk.SamInside!rem [PCTools] not-a-virus:PSWTool.Win32.SAMInside.o [Kaspersky Lab] Generic PUP.x [McAfee] Mal/Generic-A [Sophos].
MD5 of GETHASHES.EXE = D7D86B37DBD7873680E0E3695E42488B
GETHASHES.EXE size is 184320 bytes.
Full path on a computer: %TEMP%\RARSFX0\TOOLS\GETHASHES.EXE
Related Files:
%TEMP%\RARSFX0\CHARSET.TXT
%TEMP%\RARSFX0\DESCRIPT.ION
%TEMP%\RARSFX0\DICTIONARIES\INSIDEPRO.DIC
%TEMP%\RARSFX0\HASHES\TEST1.TXT
%TEMP%\RARSFX0\HASHES\TEST2.TXT
%TEMP%\RARSFX0\HASHES\TEST3.TXT
%TEMP%\RARSFX0\LANGUAGES\BELARUSIAN.LNG
%TEMP%\RARSFX0\LANGUAGES\ESTONIAN.LNG
%TEMP%\RARSFX0\LANGUAGES\FRENCH.LNG
%TEMP%\RARSFX0\LANGUAGES\GERMAN.LNG
%TEMP%\RARSFX0\LANGUAGES\ITALIAN.LNG
%TEMP%\RARSFX0\LANGUAGES\ROMANIAN.LNG
%TEMP%\RARSFX0\LANGUAGES\UKRAINIAN.LNG
%TEMP%\RARSFX0\RUSSIAN.KBT
%TEMP%\RARSFX0\SAMINSIDE.CHM
%TEMP%\RARSFX0\SAMINSIDE.EXE
%TEMP%\RARSFX0\SAMINSIDE.HASHES
%TEMP%\RARSFX0\SAMINSIDE.INI
%TEMP%\RARSFX0\SAMINSIDE.KEY
%TEMP%\RARSFX0\TOOLS\GETHASHES.EXE
%TEMP%\RARSFX0\TOOLS\GETSYSKEY.EXE
%TEMP%\RARSFX0\TOOLS\LRCONVERT.EXE
%TEMP%\RARSFX0\TOOLS\LRCONVERT.TXT
%TEMP%\RARSFX0\TOOLS\PASSTOSYSKEY.EXE
%TEMP%\S\SAM INSIDE.EXE
%TEMP%\S\SAMVX.DLL