Solved! Use 3C9CD.EXE (Virus Sality) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

3C9CD.EXE – Virus Sality removal

File MD5 Virus Alias
3C9CD.EXE 24bff3d5cc8c57db2f913fea1900bfc0 Virus Sality
3C9CD.EXE 24bff3d5cc8c57db2f913fea1900bfc0 Worm Tanatos
3C9CD.EXE 24bff3d5cc8c57db2f913fea1900bfc0 Trojan Bancos
3C9CD.EXE 24bff3d5cc8c57db2f913fea1900bfc0 Trojan Krap
3C9CD.EXE 24bff3d5cc8c57db2f913fea1900bfc0 Worm Autorun
3C9CD.EXE 24bff3d5cc8c57db2f913fea1900bfc0 Trojan Agent

3C9CD.EXE size: 356352 bytes
3C9CD.EXE hash: 24BFF3D5CC8C57DB2F913FEA1900BFC0

Created files:

C:\246706
%WinDir%\d5c76.exe
%SysDir%\10373.exe
%SysDir%\3c9cd.exe
D:\246ae5
%Temp%\{EF6D7BB3-0226-4CF7-B1E9-FBF9698E37A2}-GoogleUpdateSetup.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\b1061: 3c9cd.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe , d5c76.exe

Detected by UnHackMe:

3C9CD.EXE
Default location: %SYSDIR%\3C9CD.EXE

Dropper information:
MD5: 24bff3d5cc8c57db2f913fea1900bfc0
File size: 356352 bytes

Leave a Reply