Solved! Use KASWIY.EXE (Virus Sality) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

KASWIY.EXE – Virus Sality removal

File MD5 Virus Alias
KASWIY.EXE e702c51c5703709f15c403cf219a21b5 Virus Sality
KASWIY.EXE e702c51c5703709f15c403cf219a21b5 Trojan Downloader
KASWIY.EXE e702c51c5703709f15c403cf219a21b5 Trojan Small

KASWIY.EXE size: 65536 bytes
KASWIY.EXE hash: E702C51C5703709F15C403CF219A21B5

Created files:

%SysDir%\kaswiy.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\Type: 10000000
HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\Start: 02000000
HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\DisplayName: Vwxyabcd Fghijklmn Pqrstuv Xyabcdef Hij
HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\ImagePath: %WinDir%\System32\kaswiy.exe
HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\Description: Vwxyab Defghijk Mnopqrst Vwxy

Detected by UnHackMe:

KASWIY.EXE
Default location: %SYSDIR%\KASWIY.EXE

Dropper information:
MD5: e702c51c5703709f15c403cf219a21b5
File size: 65536 bytes

Leave a Reply