Tag Archive

Trojan win32 Pakes Cutwail gen removal

Published on July 31, 2009 By admin

Remove Trojan.Pakes , cutwail
Name: Trojan.Pakes
Threat Level: High
Description: Trojan.Pakes downloads various malware including Internet Optimizer, ISTBar, SideFind and Target Saver, which are all products of Integrated Search Technologies (IST).
Type: TT_Downloader, TT_Trojan
Also known as: Trojan.Win32.Pakes.cij, Trojan.Win32.Pakes.kra, trojan.win32.pakes.ldi, Trojan.Win32.Pakes.bzx, TrojanDropper:Win32/Cutwail.gen!I,

Threat analysis: Search ThreatExpert to view reports
Trojan.Win32.Pakes [Ikarus] is known to be created as:
%FontsDir%\3c7780c0.dll
%ProgramFiles%\internet explorer\ijl105.dll
%ProgramFiles%\internet explorer\ijl15.dll
%System%\a.exe
%System%\com\lsass.exe
%System%\com\smss.exe
%System%\dakwx.exe
%System%\digeste.dll
%System%\drivers\hcsablyr.sys
%System%\drivers\outsevwp.sys
%System%\drivers\sespodzv.sys
%System%\drivers\xaxlzacd.sys
%System%\drivers\xwlhztoo.sys
%System%\explorer32.exe
%System%\foova.exe
%System%\isyst32win.exe
%System%\kdcse.exe
%System%\kdozp.exe
%System%\l33t.exe
%System%\msansspc.dll
%System%\msdoswinsyst32.exe
%System%\msiconf.exe
%System%\msmsgs.exe
%System%\msxml71.dll
%System%\oukdfgr.exe
%System%\reader_s.exe
%System%\scrsys16_061230.scr
%System%\setup_ver1.1550.2.exe
%System%\setup_ver1.1550.21.exe
%System%\setupl.exe
%System%\syst32svchost.exe
%System%\system.exe
%System%\updatevd.exe
%System%\updwin32syst.exe
%System%\winsys16_061230.dll
%Temp%\dhl_id8612.exe
%Temp%\explorer32.exe
%Temp%\ieupdates.exe
%Temp%\loader.exe
%Temp%\ntdll64.dll
%Temp%\pinch.exe
%Temp%\u83724.exe
%Temp%\winlogon.exe
%Temp%\wmvcodec_update.exe
%UserProfile%\reader_s.exe
%Windir%\9129837.exe
%Windir%\aczjaczj.exe
%Windir%\fxstaller.exe
%Windir%\ijl105.dll
%Windir%\jbbjrjjr.exe
%Windir%\ommiglef.exe
%Windir%\regsv32.exe
%Windir%\runsql.exe
%Windir%\services.exe
%Windir%\sv.exe
%Windir%\svchost.exe
%Windir%\winlogon.exe
%Windir%\zjiabxag.exe
Notes:
%FontsDir% [...]