Maby Trouble ?

Discussion in 'other security issues & news' started by DigitaBotOne, Feb 13, 2011.

Thread Status:
Not open for further replies.
  1. DigitaBotOne

    DigitaBotOne Registered Member

    Joined:
    Jan 12, 2011
    Posts:
    8
    Hi all I have a strange file in C:\Program Files \Getii\Instfchp.exe
    200kb
    Done google search not too sure what to make of it ,

    Virus total scan clean , outpost says it is clean ,

    and my email account is empty for the first time ever>>>?

    Windows 7
    Outpost security free
     
  2. mirzarezre

    mirzarezre Registered Member

    Joined:
    Feb 14, 2011
    Posts:
    3
  3. DigitaBotOne

    DigitaBotOne Registered Member

    Joined:
    Jan 12, 2011
    Posts:
    8
    Malware Analysis Report

    • File InfoName Value
    Size 204288
    MD5 0ef4e75ed7dba84dd934ce4d8e64d2e2
    SHA1 b205e8cf0fd49b0532af91a2248c2d6e612b959f
    SHA256 fd46f18435b199a57ca6f610b15caeec73c173865491f70433e88b64b46ab46f
    Process Exited

    • Keys Created
    • Keys Changed
    • Keys Deleted
    • Values Created
    • Values Changed
    • Values Deleted
    • Directories Created
    • Directories Changed
    • Directories Deleted
    • Files Created
    • Files Changed
    • Files Deleted
    • Directories Hidden
    • Files Hidden
    • Drivers Loaded
    • Drivers Unloaded
    • Processes Created
    • Processes Terminated
    • Threads CreatedPId Process Name TId Start Start Mem Win32 Start Win32 Start Mem
    0x344 svchost.exe 0x170 0x7c810856 MEM_IMAGE 0x7c910760 MEM_IMAGE

    • Modules Loaded
    • Windows Api Calls
    • DNS Queries
    • HTTP Queries
    • VerdictAuto Analysis Verdict
    Undetected

    • Mutexes Created or OpenedPId Image Name Address Mutex Name
    0x358 C:\TEST\sample.exe 0x4025af GetiiInstffhpChecIfAlreadyRunning
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.