CRC32: 92CACC2D
MD5: CE1781764927D640244135E24DFA5F7D
SHA-1: 9A29687D462F97B2B797E0BD6BDF9CB587DF0FF5
============================================================
MD5: CE1781764927D640244135E24DFA5F7D
SHA-1: 9A29687D462F97B2B797E0BD6BDF9CB587DF0FF5
============================================================
rx.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%ProgramFiles%\XSoftware\Working\XPCSpyPro.exe
%ProgramFiles%\XSoftware\XPCSpyPro\AppSpy.dll
%ProgramFiles%\XSoftware\XPCSpyPro\IESpy.dll
%ProgramFiles%\XSoftware\XPCSpyPro\KeySpy.dll
%ProgramFiles%\XSoftware\Working\AppMon.dll
%ProgramFiles%\XSoftware\Working\IEMon.dll
%ProgramFiles%\XSoftware\Working\KeyMon.dll
%System%\systemout.exe
%System%\SysDll32.dll
%System%\rx.exe
%System%\wintft.dll
Adds the value:
"System Check" = "Rundll32.exe SysDll32.dll,SystemCheck"
"ImagePath" = "%System%\systemout.exe"
to the Windows startup registry keys.
More info: http://securityresponse.symantec.com/avc...
Removal:
Kill rx.exe process and remove rx.exe from Windows startup using antivirus (also check How To Remove section)Startup Optimizer.