MSWORKS.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

MSWORKS.EXE – Trojan Downloader removal

FileMD5Virus Alias
MSWORKS.EXE a1250dc31e01bcf3520b88b253426b58 Trojan Downloader
MSWORKS.EXE a1250dc31e01bcf3520b88b253426b58 Trojan DLOADER
MSWORKS.EXE a1250dc31e01bcf3520b88b253426b58 Trojan SuspiciousFile
MSWORKS.EXE a1250dc31e01bcf3520b88b253426b58 Trojan CI

MSWORKS.EXE size: 22016 bytes
MSWORKS.EXE hash: A1250DC31E01BCF3520B88B253426B58

Created files:

%SysDir%\MSWorks.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\MSMinerWorks64\Type: 10000000
HKLM\System\CurrentControlSet\Services\MSMinerWorks64\Start: 02000000
HKLM\System\CurrentControlSet\Services\MSMinerWorks64\DisplayName: MSMinerWorks Helper System
HKLM\System\CurrentControlSet\Services\MSMinerWorks64\ImagePath: %WinDir%\System32\MSWorks.exe
HKLM\System\CurrentControlSet\Services\MSMinerWorks64\Description: MSMinerWorks64 Helper System for X64 windows desktop

Detected by UnHackMe:

MSWORKS.EXE
Default location: %SYSDIR%\MSWORKS.EXE

Dropper information:
MD5: a1250dc31e01bcf3520b88b253426b58
File size: 22016 bytes

Leave a Reply