http://www.microsoft.com/security/porta ... 2147308562
http://www.sophos.com/en-us/threat-cent ... lysis.aspx
https://www.virustotal.com/file/DE7D591 ... /analysis/
MD5: 4d2c7f452deede232907ce3c42eee75b - Known - missing sample
MD5: c6fcea2f9bc9f471f94d3fe0ef54cc07 - Known - missing sample
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[XSECVA] = %USERPROFILE%\Application Data\XSECVA\XSECVA.EXE -S
Related:
PRC - [2012/07/06 23:55:34 | 000,205,824 | ---- | M] (System) -- C:\Users\bb\AppData\Roaming\xsecva\xsecva.exe
I suspect as related:
http://www.sophos.com/en-us/threat-cent ... lysis.aspx
https://www.virustotal.com/file/DE7D591 ... /analysis/
MD5: 4d2c7f452deede232907ce3c42eee75b - Known - missing sample
MD5: c6fcea2f9bc9f471f94d3fe0ef54cc07 - Known - missing sample
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[XSECVA] = %USERPROFILE%\Application Data\XSECVA\XSECVA.EXE -S
Related:
PRC - [2012/07/06 23:55:34 | 000,205,824 | ---- | M] (System) -- C:\Users\bb\AppData\Roaming\xsecva\xsecva.exe
I suspect as related:
Code: Select all
c:\users\bb\AppData\Roaming\Microsoft\~DFK5cd8f51.tmp
c:\users\bb\AppData\Roaming\Microsoft\1eaadjc.dll
c:\users\bb\AppData\Roaming\Microsoft\bass.dll
c:\users\bb\AppData\Roaming\Microsoft\cxaadji.dll
c:\users\bb\AppData\Roaming\Microsoft\kfgresk.dll
c:\users\bb\AppData\Roaming\Microsoft\khaadjf.dll
c:\users\bb\AppData\Roaming\Microsoft\ncaadjg.dll
c:\users\bb\AppData\Roaming\Microsoft\peaadje.dll
c:\users\bb\AppData\Roaming\Microsoft\qwadjb.dll
c:\users\bb\AppData\Roaming\Microsoft\rsaadjd.dll
c:\users\bb\AppData\Roaming\Microsoft\vqaadjh.dll
c:\users\bb\AppData\Roaming\Microsoft\wqaadjj.dll
c:\users\bb\AppData\Roaming\Microsoft\wqabdjj.dll
c:\users\bb\AppData\Roaming\Microsoft\wqacdjj.dll
c:\users\bb\AppData\Roaming\Microsoft\wqaddjj.dll
Last edited by thisisu on Wed Jul 18, 2012 9:24 am, edited 2 times in total.