winmbu.exe - Dangerous
winmbu.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
Winmbu.exe is Trojan/Backdoor.
Kill the process winmbu.exe and remove winmbu.exe from Windows startup.
Malware: ne.exe
Removed:
C:\WINDOWS\winmbu.exe – blocks firewall
Detected by UnHackMe:
Item Name: UserInit
Author: Unknown
Related File: C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\winmbu.exe
Type: UserInit Value
Item Name: winmbu.exe
Author: Unknown
Related File: C:\WINDOWS\WINMBU.EXE
Type: Detected using Heuristic Algorithm
Removal Results: Success
Number of reboot: 1
Classification:Antivirus Version Last Update Result
F-Secure 9.0.15370.0 2010.04.08 Generic.YSpammer.D19A4F35
Kaspersky 7.0.0.125 2010.04.08 Trojan.Win32.Scar.bbwe
Microsoft 1.5605 2010.04.08 Worm:Win32/Pushbot.gen!C
NOD32 5011 2010.04.08 Win32/Boberog.AK
Additional information
File size: 50688 bytes
MD5 : 0d0aa686cf4cabaa19c552cbb6c96906
SHA1 : 41b0e5e3ece7c1866b3562d3f02b73e9d6faf91f
SHA256: e2c4e89334403a2e89be0d8ffca00b2b66b3c5db37bce6570d13e62e6fa3ffde
http://greatis.com/blog/how-to-remove-ma...