MNMSRVC.VIR – Virus Expiro

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

MNMSRVC.VIR – Virus Expiro removal

File MD5 Virus Alias
MNMSRVC.VIR 5ca4b1dd2372d7a28257a585be3f00c2 Virus Expiro
MNMSRVC.VIR 5ca4b1dd2372d7a28257a585be3f00c2 Trojan SuspiciousFile

MNMSRVC.VIR size: 180224 bytes
MNMSRVC.VIR hash: 5CA4B1DD2372D7A28257A585BE3F00C2

Created files:

C:\windows\system32\cisvc.vir
C:\windows\system32\clipsrv.vir
C:\windows\system32\dllhost.exe
C:\windows\system32\dmadmin.vir
C:\windows\system32\imapi.vir
C:\windows\system32\mnmsrvc.vir
C:\windows\system32\msdtc.exe
C:\windows\system32\msiexec.vir
C:\windows\system32\svchost.vir

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\msiserver\Type: 20010000
HKLM\System\CurrentControlSet\Services\msiserver\Start: 02000000
HKLM\System\CurrentControlSet\Services\msiserver\SBIE_CheckPoint: 01000000

Detected by UnHackMe:

MNMSRVC.VIR
Default location: %SYSDIR%\MNMSRVC.VIR

Dropper information:
MD5: 0afb1ce185c539af29f774376dc45f5e
File size: 332288 bytes

Leave a Reply