Solved! Use IBM00001.DLL (Trojan Sinowal) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

IBM00001.DLL – Trojan Sinowal removal

File MD5 Virus Alias
IBM00001.DLL 45ba52d2968ed98cf95097cd21c53218 Trojan Sinowal
IBM00001.DLL 45ba52d2968ed98cf95097cd21c53218 Trojan Downloader
IBM00001.DLL 45ba52d2968ed98cf95097cd21c53218 Trojan OnLineGames
IBM00001.DLL 45ba52d2968ed98cf95097cd21c53218 Trojan Agent

IBM00001.DLL size: 68096 bytes
IBM00001.DLL hash: 45BA52D2968ED98CF95097CD21C53218

Created files:

%Program Files Common%\Microsoft Shared\Web Folders\ibm00001.dll
%Program Files Common%\Microsoft Shared\Web Folders\ibm00001.exe
%Program Files Common%\Microsoft Shared\Web Folders\ibm00002.dll
%Program Files Common%\Microsoft Shared\Web Folders\ibm00003.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\shell: explorer.exe “%Program Files Common%\Microsoft Shared\Web Folders\ibm00001.exe”
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\shell: “%Program Files Common%\Microsoft Shared\Web Folders\ibm00001.exe”

Detected by UnHackMe:

IBM00001.DLL
Default location: %PROGRAM FILES COMMON%\MICROSOFT SHARED\WEB FOLDERS\IBM00001.DLL

Dropper information:
MD5: 033ea9b29300d8616514c090906ad1c3
File size: 151040 bytes

Leave a Reply