UNICODE.LMD – Trojan SuspiciousFile

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

UNICODE.LMD – Trojan SuspiciousFile removal

FileMD5Virus Alias
UNICODE.LMD e168de3a637f74c61acc9781a19ff74e Trojan SuspiciousFile

UNICODE.LMD size: 305784 bytes
UNICODE.LMD hash: E168DE3A637F74C61ACC9781A19FF74E

Created files:

%TEMP%\ir_ext_temp_0\AutoPlay\autorun.cdd
%TEMP%\ir_ext_temp_0\AutoPlay\Buttons\1_Grey_Blue.btn
%TEMP%\ir_ext_temp_0\AutoPlay\Buttons\Back.btn
%TEMP%\ir_ext_temp_0\AutoPlay\Buttons\Exit.btn
%TEMP%\ir_ext_temp_0\AutoPlay\Buttons\Next.btn
%TEMP%\ir_ext_temp_0\AutoPlay\Docs\Developer Information\MagAPI.dll
%TEMP%\ir_ext_temp_0\AutoPlay\Plugins\CDAudio\CDAudio.lmd
%TEMP%\ir_ext_temp_0\AutoPlay\Plugins\Cursor\Cursor.lmd
%TEMP%\ir_ext_temp_0\AutoPlay\Plugins\Encoding\Encoding.lmd
%TEMP%\ir_ext_temp_0\AutoPlay\Plugins\LISTBOXEX\LISTBOXEX.APO
%TEMP%\ir_ext_temp_0\AutoPlay\Plugins\Project\Project.lmd
%TEMP%\ir_ext_temp_0\AutoPlay\Plugins\Unicode\Unicode.lmd
%TEMP%\ir_ext_temp_0\AutoPlay\Plugins\WinApi\WinApi.lmd
%TEMP%\ir_ext_temp_0\AutoPlay\Scripts\Add_Port.exe
%TEMP%\ir_ext_temp_0\autorun.exe
%TEMP%\ir_ext_temp_0\Drivers\AOTA Family\32Bit\W2K\DAN\UM_AOTL.dll
%TEMP%\ir_ext_temp_0\Drivers\AOTA Family\32Bit\W2K\DAN\UM_AOTLG.dll
%TEMP%\ir_ext_temp_0\Drivers\AOTA Family\32Bit\W2K\DEU\UM_AOTL.dll
%TEMP%\ir_ext_temp_0\Drivers\AOTA Family\32Bit\W2K\DEU\UM_AOTLG.dll
%TEMP%\ir_ext_temp_0\Drivers\AOTA Family\32Bit\W2K\disk1
%TEMP%\ir_ext_temp_0\Drivers\AOTA Family\32Bit\W2K\ENG\UM_AOTL.dll
%TEMP%\ir_ext_temp_0\Drivers\AOTA Family\32Bit\W2K\ENG\UM_AOTLG.dll
%TEMP%\ir_ext_temp_0\Drivers\AOTA Family\32Bit\W2K\FRA\UM_AOTL.dll
%TEMP%\ir_ext_temp_0\Drivers\AOTA Family\32Bit\W2K\FRA\UM_AOTLG.dll

Detected by UnHackMe:

UNICODE.LMD
Default location: %TEMP%\IR_EXT_TEMP_0\AUTOPLAY\PLUGINS\UNICODE\UNICODE.LMD

Dropper information:
MD5: 33ff3a8d270c53a0d6a1605c71320262
File size: 19939906 bytes

Leave a Reply