WRITE_HOSTS.EXE - Dangerous
WRITE_HOSTS.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
WRITE_HOSTS.EXE is known as: packed with UPX [Kaspersky Lab].
MD5 of WRITE_HOSTS.EXE = 6E737627E2FC6B68F8DC1036B9F036AB
WRITE_HOSTS.EXE size is 302813 bytes.
Full path on a computer: %TEMP%\WRITE_HOSTS.EXE
Related Files:
%APPDATA%\DEFEXTMAP.DAT
%APPDATA%\IDM\DEFEXTMAP.DAT
%APPDATA%\IDM\URLEXCLIST.DAT
%APPDATA%\IDMMZCC3\CHROME\IDMMZCC.JAR
%APPDATA%\IDMMZCC3\CHROME.MANIFEST
%APPDATA%\IDMMZCC3\COMPONENTS\IDMMZCC.DLL
%APPDATA%\IDMMZCC3\COMPONENTS2\IIDMMZCC.XPT
%APPDATA%\IDMMZCC3\COMPONENTS2\IDMHELPER.JS
%APPDATA%\IDMMZCC3\COMPONENTS2\IDMHELPER2.JS
%APPDATA%\IDMMZCC3\COMPONENTS2\IDMMZCC.DLL
%APPDATA%\IDMMZCC3\COMPONENTS2\IDMMZCC64.DLL
%APPDATA%\IDMMZCC3\COMPONENTS2\IIDMHELPER.XPT
%APPDATA%\IDMMZCC3\COMPONENTS2\IIDMHELPER2.XPT
%APPDATA%\IDMMZCC3\INSTALL.JS
%APPDATA%\IDMMZCC3\INSTALL.RDF
%APPDATA%\IDMMZCC3\META-INF\MANIFEST.MF
%APPDATA%\IDMMZCC3\META-INF\ZIGBERT.RSA
%APPDATA%\IDMMZCC3\META-INF\ZIGBERT.SF
%APPDATA%\SCHEDULER\S_1.DT
%APPDATA%\URLEXCLIST.DAT
%DESKTOPDIR%\INTERNET DOWNLOAD MANAGER.LNK
%TEMP%\D\HOSTS.EXE
%TEMP%\D\REG.EXE
%TEMP%\D\UNREG.EXE
%TEMP%\WRITE_HOSTS.EXE