Solved! Use IEXPLORER.EXE (Worm Brontok) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

IEXPLORER.EXE – Worm Brontok removal

File MD5 Virus Alias
IEXPLORER.EXE 5a2febe2d3d3e7fac678fe6bc8e6b336 Worm Brontok
IEXPLORER.EXE 5a2febe2d3d3e7fac678fe6bc8e6b336 Trojan Eldorado
IEXPLORER.EXE 5a2febe2d3d3e7fac678fe6bc8e6b336 Trojan Agent

IEXPLORER.EXE size: 87061 bytes
IEXPLORER.EXE hash: 5A2FEBE2D3D3E7FAC678FE6BC8E6B336

Created files:

C:\tiwi.exe
%WinDir%\msvbvm60.dll
%SysDir%\IExplorer.exe
%SysDir%\msvbvm60.dll
%SysDir%\shell.exe
%SysDir%\tiwi.scr
%WinDir%\tiwi.exe
%Common Startmenu%\Programs\Startup\Empty.pif
%Local AppData%\WINDOWS\cute.exe
%Local AppData%\WINDOWS\imoet.exe
%Local AppData%\WINDOWS\lsass.exe
%Local AppData%\WINDOWS\smss.exe
%Local AppData%\WINDOWS\winlogon.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\LogonUSER: %Local AppData%\WINDOWS\imoet.exe
HKCU\Control Panel\Desktop\SCRNSAVE.EXE: %WinDir%\System32\tiwi.SCR
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\tiwi: %WinDir%\tiwi
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MSMSGS: %Local AppData%\WINDOWS\winlogon.exe

Detected by UnHackMe:

IEXPLORER.EXE
Default location: %SYSDIR%\IEXPLORER.EXE

Dropper information:
MD5: 040207916cd19ad77d263dcdb1f20a00
File size: 87061 bytes

Leave a Reply