HINHEM.SCR – Virus Sality

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

HINHEM.SCR – Virus Sality removal

FileMD5Virus Alias
HINHEM.SCR 28f7694ff86ade89881ee0b7f503283a Virus Sality
HINHEM.SCR 28f7694ff86ade89881ee0b7f503283a Trojan Hllw
HINHEM.SCR 28f7694ff86ade89881ee0b7f503283a Trojan Downloader
HINHEM.SCR 28f7694ff86ade89881ee0b7f503283a Worm Autoit
HINHEM.SCR 28f7694ff86ade89881ee0b7f503283a Worm Autorun
HINHEM.SCR 28f7694ff86ade89881ee0b7f503283a Trojan Agent

HINHEM.SCR size: 295849 bytes
HINHEM.SCR hash: 28F7694FF86ADE89881EE0B7F503283A

Created files:

C:\3947db
%WinDir%\hinhem.scr
%WinDir%\scvhosts.exe
%SysDir%\blastclnnn.exe
%SysDir%\scvhosts.exe
%TEMP%\00394027_Rar\28F7694FF86ADE89881EE0B7F503283A.EXE
D:\394b89
D:\cert\VBoxCertUtil.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe scvhosts.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Yahoo Messengger: %WinDir%\System32\scvhosts.exe

Detected by UnHackMe:

HINHEM.SCR
Default location: %WinDir%\HINHEM.SCR

Dropper information:
MD5: 28f7694ff86ade89881ee0b7f503283a
File size: 295849 bytes

Leave a Reply