WMDRTC32.DLL – Virus Sality

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

WMDRTC32.DLL – Virus Sality removal

FileMD5Virus Alias
WMDRTC32.DLL 03ebc053c8eec6b4f4afbbb5dc64b169 Virus Sality
WMDRTC32.DLL 03ebc053c8eec6b4f4afbbb5dc64b169 Trojan Generic
WMDRTC32.DLL 03ebc053c8eec6b4f4afbbb5dc64b169 Worm AMN
WMDRTC32.DLL 03ebc053c8eec6b4f4afbbb5dc64b169 Trojan Agent

WMDRTC32.DLL size: 40960 bytes
WMDRTC32.DLL hash: 03EBC053C8EEC6B4F4AFBBB5DC64B169

Created files:

C:\dir\install\svchost\svchost.exe
%SysDir%\wmdrtc32.dll
%SysDir%\wmdrtc32.dl_

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{TRP63K8M-GITK-J0MA-64UC-S6E5CB7B4P0H}\StubPath: c:\dir\install\svchost\svchost.exe Restart
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: 63003A005C006400690072005C0069006E007300740061006C006C005C0073007600630068006F00730074005C0073007600630068006F00730074002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: 63003A005C006400690072005C0069006E007300740061006C006C005C0073007600630068006F00730074005C0073007600630068006F00730074002E006500780065000000

Detected by UnHackMe:

WMDRTC32.DLL
Default location: %SYSDIR%\WMDRTC32.DLL

Dropper information:
MD5: e2936b550c2d1e53ab9b4d41aad8c9fe
File size: 430080 bytes

Leave a Reply