VSCXA.EXE - Dangerous
VSCXA.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
VSCXA.EXE is known as: Virus.Win32.Sality.bh [Kaspersky Lab] W32/Sality.dr [McAfee] Virus:Win32/Sality.AT [Microsoft] Win32.Sality [Ikarus] Win32/Kashu.E [AhnLab].
MD5 of VSCXA.EXE = 7F1C6B4C20EA8EF364D4499D66CF1DA7
VSCXA.EXE size is 103140 bytes.
Full path on a computer: C:\VSCXA.EXE
Related Files:
C:\AUTORUN.INF
C:\BA2CF8EBC981D0E1DE10B01DE36EB333\SPUNINST.EXE
C:\CB60F\BLUTOOTH.CHM
C:\CB60F\BTH.INF
C:\CB60F\BTHCI.DLL
C:\CB60F\BTHENUM.SYS
C:\CB60F\BTHMODEM.SYS
C:\CB60F\BTHPORT.SYS
C:\CB60F\BTHPRINT.INF
C:\CB60F\BTHPRINT.SYS
C:\CB60F\BTHSERV.DLL
C:\CB60F\BTHUSB.SYS
C:\CB60F\BTSETUP.EXE
C:\CB60F\HDWWIZ.CPL
C:\CB60F\HIDBTH.INF
C:\CB60F\HIDBTH.SYS
C:\CB60F\HIDCLASS.SYS
C:\CB60F\IRPROPS.CPL
C:\CB60F\MDMBTMDM.INF
C:\CB60F\MDMINST.DLL
C:\CB60F\PRINTUI.DLL
C:\CB60F\Q323183.CAB
C:\CB60F\RFCOMM.SYS
C:\CB60F\SPMSG.DLL
C:\CB60F\SPUNINST.EXE
C:\CB60F\SYMBOLS\CPL\HDWWIZ.PDB
C:\CB60F\SYMBOLS\CPL\IRPROPS.PDB
C:\CB60F\SYMBOLS\DLL\BTHCI.PDB
C:\CB60F\SYMBOLS\DLL\BTHSERV.PDB
C:\CB60F\SYMBOLS\DLL\MDMINST.PDB
C:\CB60F\SYMBOLS\DLL\PRINTUI.PDB
C:\CB60F\SYMBOLS\DLL\USBMON.PDB
C:\CB60F\SYMBOLS\DLL\WSHBTH.PDB
C:\CB60F\SYMBOLS\EXE\BTSETUP.PDB
C:\CB60F\SYMBOLS\SYS\BTHENUM.PDB
C:\CB60F\SYMBOLS\SYS\BTHMODEM.PDB
C:\CB60F\SYMBOLS\SYS\BTHPORT.PDB
C:\CB60F\SYMBOLS\SYS\BTHPRINT.PDB
C:\CB60F\SYMBOLS\SYS\BTHUSB.PDB
C:\CB60F\SYMBOLS\SYS\HIDBTH.PDB
C:\CB60F\SYMBOLS\SYS\HIDCLASS.PDB
C:\CB60F\SYMBOLS\SYS\RFCOMM.PDB
C:\CB60F\TDIBTH.INF
C:\CB60F\UPDATE\EULA.TXT
C:\CB60F\UPDATE\Q323183.CAT
C:\CB60F\UPDATE\SPCUSTOM.DLL
C:\CB60F\UPDATE\UPDATE.EXE
C:\CB60F\UPDATE\UPDATE.INF
C:\CB60F\UPDATE\UPDATE.VER
C:\CB60F\USBMON.DLL
C:\CB60F\WSHBTH.DLL
C:\CB60F\XPSP2RES.DLL
%TEMP%\00033BF1_RAR\[FILENAME OF THE SAMPLE #1]
C:\VSCXA.EXE
%WINDIR%\Q323183.LOG