DOTNETSETUP.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DOTNETSETUP.EXE – Trojan Downloader removal

FileMD5Virus Alias
DOTNETSETUP.EXE 86b303089d2517016d78146e3b4649c7 Trojan Downloader

DOTNETSETUP.EXE size: 479744 bytes

Created files:

%Temporary Internet Files%\Content.IE5\1HVEIEYW\dotnetfx35setup[1].exe
%TEMP%\IXP000.TMP\dotnetfx35setup.exe
%TEMP%\IXP000.TMP\DotNetSetup.exe
%TEMP%\IXP000.TMP\InstallerAny.exe
%TEMP%\IXP000.TMP\Interop.IWshRuntimeLibrary.dll
%TEMP%\IXP000.TMP\MailBee.NET.dll
%TEMP%\IXP000.TMP\WSysLib.Installer.dll
%TEMP%\IXP000.TMP\WSysLib.Installer.Runtimes.wSetup.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0: rundll32.exe %WinDir%\System32\advpack.dll,DelNodeRunDLL32 “%TEMP%\IXP000.TMP\”

Detected by UnHackMe:

DOTNETSETUP.EXE
Default location: %TEMP%\IXP000.TMP\DOTNETSETUP.EXE

Leave a Reply