Virtumonde
Process Files:
Nero_Burning_Rom_Ultra_Edition_6.6.0.6_serial_number.txt[1].exe
Windows_XP_SP2_Professional_Edition_Corporate_serial_number.txt[2].exe
ces005dr.exe
nnx22011.exe
kopCFEWV.exe
castlecops[1].exe
unknown.exe
svci.exe
psdrv.exe
rasrun.exe
nwonknu.exe
editpad.exe
quicken.exe
winhost.exe
editpad.exewindowsupd2.exe
quicken.exe
winhost.exe
windowsupd2.exe
Virtumonde
Registry Entries:
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\efcdaab
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\khffefd
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\cbxussr
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\tuvvsrp
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\gebyxuu
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\ssqnolm
200D0AAD-71B1-51C9-DDB0-092BA4662A54
01CD0B31-9154-45F2-9414-F5D64B74EAF6
AB30E818-2B0F-4336-BB29-35D245598EDB
634BBAB7-3F60-4426-944F-A62B9007F67F
C408EC5B-CC5E-451D-B831-6DB83DA47244
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\hggdefc
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\geebc
232D2677-68EE-4FA1-B988-279EBC8969ED
A93EE73A-8FEB-47CD-BDF1-E75A0B6BEF8C
90624170-D668-409E-A2F5-C0710044760F
3385764C-85FC-45CC-B290-E97646306BB2
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtttqr
6730A59E-FBA3-4EEC-B564-5F05EF8EF39C
582C46EE-9E66-4DE0-92A5-34B971099C0C
429E0606-5905-4CCD-998A-9D2C29DE6F33
B1F4D9B0-7300-408A-B70A-677CC7276EF6
90375CC7-C153-4D5C-B81D-C4011A3C16D3
2D04C025-C1A3-4DC1-81D8-A10EFEAFA699
DA0053C8-1501-48C6-BD86-167AA3DEC119
A3DA48A6-8C7B-43CB-B31B-F28005EF8DFD
9DC8B477-C55C-4373-953D-8913334A8D8B
Other
Virtumonde Files:
%SYSTEMROOT%\system32\mojbopil.dll
%SYSTEMROOT%\system32\aecggnuj.dll
%SYSTEMROOT%\system32\ssqrSMee.dll
%SYSTEMROOT%\system32\khfcBQjk.dll
%SYSTEMROOT%\system32\qoMfdaWQ.dll
%SYSTEMROOT%\system32\zwpmbd.dll
%SYSTEMROOT%\system32\ltyolghw.dll
%SYSTEMROOT%\system32\jwijhtyf.dll
%SYSTEMROOT%\system32\cssifsik.dll
%SYSTEMROOT%\system32\tqabkkhc.dll
%SYSTEMROOT%\system32\rqRIbArq.dll
%SYSTEMROOT%\system32\mzqlig.dll
%SYSTEMROOT%\system32\iifefeBt.dll
%SYSTEMROOT%\system32\pmnoMgEw.dll
%SYSTEMROOT%\system32\dsnltn.dll
%SYSTEMROOT%\system32\rqRJDwvU.dll
dsnltn.dll
%SYSTEMROOT%\system32\vtUmmNFw.dll
%SYSTEMROOT%\system32\zntdkn.dll
%SYSTEMROOT%\system32\vtUmNGwX.dll
%SYSTEMROOT%\system32\wowoxx.dll
%SYSTEMROOT%\system32\vtUkhETm.dll
%SYSTEMROOT%\system32\efcASmKd.dll
%SYSTEMROOT%\system32\fdswmgss.dll
%SYSTEMROOT%\system32\pfqjbewx.dll
%SYSTEMROOT%\system32\yayxyvwx.dll
%SYSTEMROOT%\system32\awtsPJcA.dll
%SYSTEMROOT%\system32\bqjdrh.dll
Warning
Removing
registry entries can be very dangerous when done manually.
You
can accidentally cause windows errors, blue screens, even the collapse
of your hard drive. Procede with caution!
.