6B08C812d01
* jQuery 1.2.5 - New Wave Javascript
*
* Copyright (c) 2008 John Resig (jquery.com)
* Dual licensed under the MIT (MIT-LICENSE.txt)
* and GPL (GPL-LICENSE.txt) licenses.
BB2E8847d01
Binary data that could be encoded. Did not try to decode.
599999AFd01.png
Nothing but white graphic
30C0D48Dd01
Graphic of orange shield that could be associated with a rogue anti malware
setup_build7_195.exe
0 hits on Virus Total
Windows Protection Suite installer
Mutex:
VirusDoctorInstallerMutex
Communicates with:
prestotunerst.cn
mysecurityguru.cn
securefield.net
update1.windowsprotectionsuite.com
update2.windowsprotectionsuite.com
pay1.winprotectionsuite.com
Creates folder:
C:\Documents and Settings\All Users\Application Data\XXXXXXX
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
WINPS = ""C:\Documents and Settings\All Users\Application Data\XXXXXXX\WinProtector.exe"
/s"
Executes command:
taskkill.exe "C:\WINDOWS\system32\taskkill.exe" /F /IM MSASCui* /IM avg* /IM ash* /IM
McSA*
Where XXXXXXX equals something like...
e394af6
e4a12b7
7439e16
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV -
http://www.pctipp.ch/downloads/dl/35905.asp