POSTILDLL.DLL – Trojan SuspiciousFile

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

POSTILDLL.DLL – Trojan SuspiciousFile removal

FileMD5Virus Alias
POSTILDLL.DLL 3e5cc62def8c742210a36091f5b552ae Trojan SuspiciousFile

POSTILDLL.DLL size: 36864 bytes
POSTILDLL.DLL hash: 3E5CC62DEF8C742210A36091F5B552AE

Created files:

%SysDir%\eWebEditorClient.dll
%SysDir%\NewvCommon.ocx
%SysDir%\NewvRecorder.ocx
%SysDir%\WebOffice.ocx
%SysDir%\WinLockDll.dll
%TEMP%\IXP000.TMP\CloseIEWindows.exe
%TEMP%\IXP000.TMP\eWebEditorClient.dll
%TEMP%\IXP000.TMP\NewvCommon.ocx
%TEMP%\IXP000.TMP\NewvRecorder.ocx
%TEMP%\IXP000.TMP\SmartClientSetting.exe
%TEMP%\IXP000.TMP\WebOffice.ocx
%TEMP%\IXP000.TMP\WinLockDll.dll
%TEMP%\PostilDll.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0: rundll32.exe %WinDir%\System32\advpack.dll,DelNodeRunDLL32 “%TEMP%\IXP000.TMP\”

Detected by UnHackMe:

POSTILDLL.DLL
Default location: %TEMP%\POSTILDLL.DLL

Dropper information:
MD5: b9169be249767f7927590d765a2f7466
File size: 1021952 bytes

Leave a Reply