Solved! Use REGSVR.EXE (Worm Autoit) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

REGSVR.EXE – Worm Autoit removal

File MD5 Virus Alias
REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Worm Autoit
REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Trojan Generic
REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Trojan Hllw
REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Trojan Eldorado
REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Worm Autorun
REGSVR.EXE d837896d7b99589cf6fbfc589cd5e15d Trojan Agent

REGSVR.EXE size: 2086656 bytes
REGSVR.EXE hash: D837896D7B99589CF6FBFC589CD5E15D

Created files:

%WinDir%\regsvr.exe
%SysDir%\28463\svchost.001
%SysDir%\regsvr.exe
%SysDir%\svchost .exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe regsvr.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Msn Messsenger: %WinDir%\System32\regsvr.exe

Detected by UnHackMe:

REGSVR.EXE
Default location: %WinDir%\REGSVR.EXE

Dropper information:
MD5: d837896d7b99589cf6fbfc589cd5e15d
File size: 2086656 bytes

Leave a Reply