WINRRLH.EXE - Dangerous
WINRRLH.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
WINRRLH.EXE is known as: Hacktool.Proxy [PCTools] Hacktool.Proxy [Symantec] Mal/TinyDL-T [Sophos] Virus.Win32.Sality [Ikarus] packed with UPX [Kaspersky Lab].
MD5 of WINRRLH.EXE = 587C99603B273107779F1CDD37C37AD8
WINRRLH.EXE size is 12970 bytes.
Full path on a computer: %TEMP%\WINRRLH.EXE
Related Files:
C:\AUTORUN.INF
C:\BRAEQ.PIF
%WINDIR%\TEMP\0KFP.EXE
%TEMP%\M9NRWPBH.EXE
%TEMP%\MOUSEDRIVER.BAT
%TEMP%\WINRRLH.EXE
%TEMP%\YQ4XR08WV.BAT
%FONTSDIR%\SERVICES.EXE
%SYSTEM%\NWCWKS.DLL
%SYSTEM%\ZMGN5T2.LOG
%WINDIR%\TEMP\264CNY34A.EXE
%WINDIR%\TEMP\CONIMA.EXE
%WINDIR%\TEMP\INLOG
%WINDIR%\TEMP\INPUT.BAT
%WINDIR%\TEMP\LOCALACCOUNTAUTHORITY.BAT
%WINDIR%\TEMP\LSSAS.EXE
%WINDIR%\TEMP\MANAGER.EXE
%WINDIR%\TEMP\MLOG
%WINDIR%\TEMP\MOUSEDRIVER.BAT
%WINDIR%\TEMP\PLUG.BAT
%WINDIR%\TEMP\YLOG