Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

XXX_FB.DLL is Trojan Pws

$
0
0

The file XXX_FB.DLL is identified as a virus dropper.
The dropper XXX_FB.DLL is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.
The file XXX_FB.DLL loads into the computer memory and tries to connect to the dangerous web site.
Usually the XXX_FB.DLL dropper does not infect the files on the computer and does not replicate itself on other computers.
Kill the XXX_FB.DLL process and delete the file XXX_FB.DLL.

Malware Analysis of XXX_FB.DLL
Full path on a computer: %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\XXX_FB.DLL

Detected by UnHackMe:

XXX_FB.DLL
Default location: %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\XXX_FB.DLL

Removal Results: Success
Number of reboot: 1

XXX_FB.DLL is known as:

Trojan.Pws

How to quickly detect XXX_FB.DLL presence?
Files:
  • %TEMP%\CAB7.TMP
  • %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\P2P.DLL
  • %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\G711CODC.AX
  • %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\SAVEDUMP.EXE
  • %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\XXX_FB.DLL


Viewing all articles
Browse latest Browse all 38585

Trending Articles