VMDIR.EXE - Dangerous
VMDIR.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
VMDIR.EXE is known as: Malware.Sality [PCTools] W32.Sality.AE [Symantec] Virus.Win32.Sality.bh [Kaspersky Lab] W32/Sality.gen.e [McAfee] Mal/Sality-D [Sophos] Virus:Win32/Sality.AT [Microsoft] Virus.Win32.Sality [Ikarus] Win32/Kashu.E [AhnLab].
MD5 of VMDIR.EXE = BDF0EE20CDAD56EA5876A570CD69A0FF
VMDIR.EXE size is 130787 bytes.
Full path on a computer: C:\VMDIR.EXE
Related Files:
C:\AUTORUN.INF
%TEMP%\1AVS.LOG
%TEMP%\MOUSEDRIVER.BAT
%TEMP%\PIWPJSZON.BAT
%WINDIR%\TEMP\QTFCYYP.EXE
%TEMP%\URRQTJEJ4.EXE
%TEMP%\VN1UOX5TS.BAT
%TEMP%\WINXGRDO.EXE
%WINDIR%\TEMP\ZLY0I.EXE
C:\VMDIR.EXE
%SYSTEM%\NWSAPAGENTS.DLL
%WINDIR%\TEMP\1AVS.LOG
%WINDIR%\TEMP\36WRWHQP0.EXE
%WINDIR%\TEMP\IS9ASY7Q4.EXE
%WINDIR%\TEMP\MANAGEE.EXE
%WINDIR%\TEMP\MLOG
%WINDIR%\TEMP\MOUSEDRIVER.BAT
%WINDIR%\TEMP\PLUG.BAT
%WINDIR%\TEMP\QAL8CPVOA.EXE