PWSERVICE.EXE – Suspicious File

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

PWSERVICE.EXE – Suspicious File removal

File MD5 Virus Alias
PWSERVICE.EXE 1060a6528bccea8336b3a8c6750d5c50 Suspicious File
PWSERVICE.EXE 1060a6528bccea8336b3a8c6750d5c50 Trojan Generic
PWSERVICE.EXE 1060a6528bccea8336b3a8c6750d5c50 Trojan Agent

PWSERVICE.EXE size: 45056 bytes
PWSERVICE.EXE hash: 1060A6528BCCEA8336B3A8C6750D5C50

Created files:

%TEMP%\cachedump.exe
%TEMP%\fgexec.exe
%TEMP%\lsaext.dll
%TEMP%\pstgdump.exe
%TEMP%\pwdump.exe
%TEMP%\pwservice.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\CacheDump\Type: 10000000
HKLM\System\CurrentControlSet\Services\CacheDump\Start: 03000000
HKLM\System\CurrentControlSet\Services\CacheDump\DisplayName: CacheDump
HKLM\System\CurrentControlSet\Services\CacheDump\ImagePath: %TEMP%\cachedump.exe -s

Detected by UnHackMe:

PWSERVICE.EXE
Default location: %TEMP%\PWSERVICE.EXE

Dropper information:
MD5: b6c171adc5cffb3f6386778701bd1ba5
File size: 573440 bytes

Leave a Reply