MANUALINSTALLER.EXE – Trojan XPACK

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

MANUALINSTALLER.EXE – Trojan XPACK removal

FileMD5Virus Alias
MANUALINSTALLER.EXE 69aefa32331b44ca80a96001e0645bd4 Trojan XPACK

MANUALINSTALLER.EXE size: 330752 bytes
MANUALINSTALLER.EXE hash: 69AEFA32331B44CA80A96001E0645BD4

Created files:

%TEMP%\IXP000.TMP\gssecuforjobkorea.sys
%TEMP%\IXP000.TMP\gssecuforjobkorea64.sys
%TEMP%\IXP000.TMP\manualinstaller.exe
%TEMP%\IXP000.TMP\webprotectoragent.exe
%TEMP%\IXP000.TMP\webprotectoragent64.exe
%TEMP%\IXP000.TMP\webprotectorcontrolex.ocx
%TEMP%\IXP000.TMP\webprotectorhook.dll
%TEMP%\IXP000.TMP\webprotectorhook64.dll
%TEMP%\IXP000.TMP\webprotectorserver.dll
%TEMP%\IXP000.TMP\webprotectorserver64.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0: rundll32.exe %WinDir%\System32\advpack.dll,DelNodeRunDLL32 “%TEMP%\IXP000.TMP\”

Detected by UnHackMe:

MANUALINSTALLER.EXE
Default location: %TEMP%\IXP000.TMP\MANUALINSTALLER.EXE

Dropper information:
MD5: fab4fa69b3c3818c29c2dab29896d4d4
File size: 875936 bytes

Leave a Reply