Solved! Use MICROSOFT.EXE (Backdoor Poison) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

MICROSOFT.EXE – Backdoor Poison removal

File MD5 Virus Alias
MICROSOFT.EXE 02d94b0be99cf2fc6651b9c30d742f9d Backdoor Poison
MICROSOFT.EXE 02d94b0be99cf2fc6651b9c30d742f9d Trojan Generic
MICROSOFT.EXE 02d94b0be99cf2fc6651b9c30d742f9d Trojan Agent
MICROSOFT.EXE 02d94b0be99cf2fc6651b9c30d742f9d Trojan Crypt
MICROSOFT.EXE 02d94b0be99cf2fc6651b9c30d742f9d Virus Vbcrypt
MICROSOFT.EXE 02d94b0be99cf2fc6651b9c30d742f9d Trojan Refroso

MICROSOFT.EXE size: 106496 bytes
MICROSOFT.EXE hash: 02D94B0BE99CF2FC6651B9C30D742F9D

Created files:

%WinDir%\5s3@ksa.gs.exe
%WinDir%\microsoft.exe
%SysDir%\5s3@ksa.gs.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe 5s3@ksa.gs.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Yahoo Messengger: %WinDir%\System32\5s3@ksa.gs.exe

Detected by UnHackMe:

MICROSOFT.EXE
Default location: %WinDir%\MICROSOFT.EXE

Dropper information:
MD5: e9e3e38be8ac771e7f11f068936a6166
File size: 680166 bytes

Leave a Reply