NETCOX.EXE - Dangerous
NETCOX.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
NETCOX.EXE is known as: Trojan-PSW.Generic [PCTools] Infostealer [Symantec] Trojan-Spy.Win32.WinSpy.ary [Kaspersky Lab] Generic.dx!ttp [McAfee] Mal/Generic-L [Sophos] Trojan-Spy.Win32.WinSpy [Ikarus].
MD5 of NETCOX.EXE = 564B1ED989E31FA12355F733A9F80C32
NETCOX.EXE size is 40960 bytes.
Full path on a computer: %WINDIR%\NETCOX.EXE
Related Files:
%TEMP%\COMPRESS0\WEBEN.DLL
%TEMP%\COMPRESS0\CLIPSRV.EXE
%TEMP%\COMPRESS0\UNIN.DLL
%TEMP%\COMPRESS0\SCDAY.DLL
%TEMP%\COMPRESS0\FTIN.DLL
%TEMP%\COMPRESS0\FTPA.DLL
%TEMP%\COMPRESS0\FTUS.DLL
%WINDIR%\HPVERT.DLL
%TEMP%\COMPRESS0\INMSG.DLL
%PROGRAMFILES%\SATACONTROL\LIVE.EXE
%TEMP%\COMPRESS0\MAIL.DLL
%TEMP%\COMPRESS0\MSWINSCK.OCX
%TEMP%\COMPRESS0\PICTURE.DLL
%TEMP%\COMPRESS0\PORT.DLL
%TEMP%\COMPRESS0\USHOST.DLL
%PROGRAMFILES%\SATACONTROL\RDS.EXE
%WINDIR%\REFSDM.DLL
%TEMP%\COMPRESS0\SSAP.DLL
%TEMP%\COMPRESS0\RVHOST.DLL
%TEMP%\COMPRESS0\RVPORT.DLL
%TEMP%\COMPRESS0\RWCI.DLL
%TEMP%\COMPRESS0\RWCS.DLL
%TEMP%\COMPRESS0\SCINT.DLL
%TEMP%\COMPRESS0\SCLOC.DLL
%PROGRAMFILES%\SATACONTROL\SERVICES32.EXE
%TEMP%\COMPRESS0\SID2.DLL
%TEMP%\COMPRESS0\TYPE.DLL
%WINDIR%\NETCOX.EXE
%TEMP%\COMPRESS0\USER.DLL
%PROGRAMFILES%\SATACONTROL\CMSS.EXE
%TEMP%\COMPRESS0\ZIPINFO.TXT
%TEMP%\NSA2.TMP
%PROGRAMFILES%\ACCESSORIES\COMMON\28 MAY 11 02_18_32 %USERNAME% .TCM
%PROGRAMFILES%\ACCESSORIES\COMMON\CHAT_LOG.TXT
%PROGRAMFILES%\ACCESSORIES\COMMON\DESKTOP.INI
%PROGRAMFILES%\ACCESSORIES\COMMON\KB_LOG.TXT
%PROGRAMFILES%\ACCESSORIES\COMMON\LOSTSTOLENPC.TXT
%PROGRAMFILES%\ACCESSORIES\COMMON\ONLINE_TIME.TXT
%PROGRAMFILES%\ACCESSORIES\COMMON\PC_ACTIVE_TIME.TXT
%PROGRAMFILES%\ACCESSORIES\COMMON\WEBSITES_DETAIL.TXT
%PROGRAMFILES%\ACCESSORIES\COMMON\WEBSITES_SUMMARY.TXT