Dangerous: YES
Associated Files:
convite.exe, downloads_r.com, Download_Imagem.zip. Ifn.ini, Mast.ini, sxmc.ini, diagx3d.dll, smastsj.exe, unchsy.exe
File Behavior:
The Process is packed and/or encrypted using a software packing process.
Creation and Registration of a Browser Helper Object in Internet Explorer.
This process creates other processes on disk.
Writes to another Process's Virtual Memory (Process Hijacking).
Can communicate with other computer systems using HTTP protocols.
Installs a browser helper object (BHO).
Creates or uses a background service to access the Internet using HTTP protocols.
Malware Name:
Win32:Spyware-Gen, Win32:Bancos-BLF
Malware Type:
Trojan Horse, Infection, PHISH
File Location:
C:\Windows\Ifn.ini
C:\Windows\system32\smastsj.exe
C:\Windows\system32\unchsy.exe
C:\Windows\System32\Mast.ini
C:\Windows\System32\sxmc.ini
C:\Windows\System32\DirectX\Dinput\diagx3d.dll
Symptoms:
When you open your mail a friend from your contact list will send you an e-mail saying something like - Example:
OIII...!! TUDO BEM? Pois é eu sumi... mas eu não esqueci |
Associated Web Sites:
http://mundopumavirtualx02.in |
Removal Procedure:
1. Use Prevx 3.0 (Download-PREVXCSIFREE.exe) to try and remove this virus Click Here to select a different language.
2. If Prevx dosen't work for you download ComboFix and save the file to your desktop, rename it from Combofix to Combo-Fix. - It' important you rename it to Combo-Fix during the download and not after or winupgro will corrupte it making it unable to open.
Try some online free virus scans:
Kaspersky
ESET Smart Security/ESET NOD32 Antivirus
Trend Micro HouseCall
AVG LinkScanner
F-Secure
BitDefender
4 comments
Write commentsthanks for this you gave soom good info here that i needed
Replyi think its removed now i'll see how it go's
Combo-Fix Worked Thank You!
Replycool gone! thanks alot
ReplyCombo-Fix worked, thank you!
ReplyHowever, the ones that I tried but seemed to fail: spyboot, Malwarebyte AntiMalware, cc cleaner, exterminate-it (because you must pay and it may or may not work), Prevx (same as exterminate-it).
Make sure all cookies and history is deleted before using any tool to remove stuff, stop the antivirus before using any tool, or better yet, delete and install again later
Hope this help
C. Francis