DWM.EXE – Trojan Eldorado

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DWM.EXE – Trojan Eldorado removal

FileMD5Virus Alias
DWM.EXE 0b2180fb0c8d5ad579a31b2fc8d8c73a Trojan Eldorado

DWM.EXE size: 37053 bytes
DWM.EXE hash: 0B2180FB0C8D5AD579A31B2FC8D8C73A

Created files:

%WinDir%\system\dwm.exe
%TEMP%\ddid

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\darkness\Type: 10010000
HKLM\System\CurrentControlSet\Services\darkness\Start: 02000000
HKLM\System\CurrentControlSet\Services\darkness\DisplayName: IpSectPro service
HKLM\System\CurrentControlSet\Services\darkness\ImagePath: %WinDir%\System\dwm.exe

Detected by UnHackMe:

DWM.EXE
Default location: %WinDir%\SYSTEM\DWM.EXE

Dropper information:
MD5: 0b2180fb0c8d5ad579a31b2fc8d8c73a
File size: 37053 bytes

Leave a Reply