How to remove 6rxt26.exe

File size: 107994 bytes
CRC32: 90B6E631
MD5: 676669456528CA4778B740203C4C8341
SHA-1: D17B9D12D98B13193D50B78AEAA80116DF88EFDE
===================================================
Aliases:

  • a-squared 4.5.0.24 2009.09.17 Trojan.Win32.Inhoo!IK
  • AhnLab-V3 5.0.0.2 2009.09.16 Win-Trojan/Magania.107994
  • AntiVir 7.9.1.18 2009.09.17 TR/Crypt.ZPACK.Gen
  • Antiy-AVL 2.0.3.7 2009.09.17 Trojan/Win32.Magania.gen
  • Authentium 5.1.2.4 2009.09.17 W32/SuspPack.AG.gen!Eldorado
  • Avast 4.8.1351.0 2009.09.16 Win32:Kamso
  • AVG 8.5.0.412 2009.09.16 Generic14.NSU
  • BitDefender 7.2 2009.09.17 Trojan.Generic.2272530
  • CAT-QuickHeal 10.00 2009.09.17 TrojanGameThief.Magania.bsib
  • ClamAV 0.94.1 2009.09.17 -
  • Comodo 2345 2009.09.17 TrojWare.Win32.Trojan.Agent.Gen
  • DrWeb 5.0.0.12182 2009.09.17 Trojan.PWS.Wsgame.12661
  • eSafe 7.0.17.0 2009.09.16 Win32.TRCrypt.ZPACK
  • eTrust-Vet 31.6.6742 2009.09.16 Win32/Frethog.EYZ
  • F-Prot 4.5.1.85 2009.09.16 W32/SuspPack.AG.gen!Eldorado
  • Fortinet 3.120.0.0 2009.09.16 SPY/Magania
  • GData 19 2009.09.17 Trojan.Generic.2272530
  • Ikarus T3.1.1.72.0 2009.09.17 Trojan.Win32.Inhoo
  • Jiangmin 11.0.800 2009.09.17 Trojan/PSW.Magania.whn
  • K7AntiVirus 7.10.846 2009.09.16 Trojan-PSW.Win32.Magania.bsib
  • Kaspersky 7.0.0.125 2009.09.17 Trojan-GameThief.Win32.Magania.bsib
  • McAfee 5743 2009.09.16 Generic PWS.ak
  • McAfee+Artemis 5743 2009.09.16 Generic PWS.ak
  • McAfee-GW-Edition 6.8.5 2009.09.16 Heuristic.LooksLike.Trojan.Dropper.Zlob.B
  • Microsoft 1.5005 2009.09.17 Worm:Win32/Taterf.B
  • NOD32 4432 2009.09.17 Win32/PSW.OnLineGames.NNU
  • Norman 6.01.09 2009.09.16 W32/Agent.dam
  • nProtect 2009.1.8.0 2009.09.17 Trojan/W32.Agent.107994
  • Panda 10.0.2.2 2009.09.16 Trj/Lineage.BZE
  • PCTools 4.4.2.0 2009.09.16 -
  • Prevx 3.0 2009.09.17 High Risk Cloaked Malware
  • Rising 21.47.31.00 2009.09.17 Trojan.PSW.Win32.GameOLx.hy
  • Sophos 4.45.0 2009.09.17 Mal/EncPk-JS
  • Sunbelt 3.2.1858.2 2009.09.17 BehavesLike.Win32.Malware (v)
  • Symantec 1.4.4.12 2009.09.17 Trojan Horse
  • TheHacker 6.3.4.4.404 2009.09.15 Trojan/Magania.bsib
  • TrendMicro 8.950.0.1094 2009.09.17 TROJ_GAMETHI.RPF
  • VBA32 3.12.10.10 2009.09.17 Trojan-GameThief.Win32.Magania.bsib
  • ViRobot 2009.9.17.1940 2009.09.17 Trojan.Win32.PSWMagania.107994
  • VirusBuster 4.6.5.0 2009.09.16 Trojan.PWS.Magania.QYH
------------------------------------------------------------------------
Create file
C:\DOCUME~1\ADMINI~1\LOCALS~1\temp\herss.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\temp\cvasds0.dll
X:\6rxt26.exe
X:\autorun.inf

Download file
C:\DOCUME~1\ADMINI~1\LOCALS~1\temp\am1.rar > am1.exe

Keys added
HKLM\SOFTWARE\Classes\CLSID\MADOWN
HKLM\SYSTEM\ControlSet001\Services\AVPsys
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys

Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Hidden: 0x00000002
HKU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
ShowSuperHidden: 0x00000000
HKU\\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun: 0x00000091

Related Posts Plugin for WordPress, Blogger...
Disclaimer
All the contents posted here are found from various Search Engines blogs and forums. The Webmaster of this blog takes no responsibility what so ever for any of the content (image/audio/video). If you find some content inappropriate or if there is any violation of copyright, kindly contact the host of the content (image/audio/video) to remove it from their server.
 
✖ SedutMediaLink ✖ - Templates Novo Blogger 2008
This template is brought to you by : allblogtools.com Blogger Templates