62.EXE – Worm Ainslot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

62.EXE – Worm Ainslot removal

FileMD5Virus Alias
62.EXE 9112009e7d9c5ff25ae978beb43e00f8 Worm Ainslot
62.EXE 9112009e7d9c5ff25ae978beb43e00f8 Trojan Generic
62.EXE 9112009e7d9c5ff25ae978beb43e00f8 Trojan CI
62.EXE 9112009e7d9c5ff25ae978beb43e00f8 Trojan Agent

62.EXE size: 217424 bytes
62.EXE hash: 9112009E7D9C5FF25AE978BEB43E00F8

Created files:

%AppData%\62.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{58A4FBC3-BFD8-4CBC-CEF4-FD3BDF548BC9}\StubPath: %WinDir%\System32\config\Systemprofile\Application Data\62.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\Windows Defender: %WinDir%\System32\config\Systemprofile\Application Data\62.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Defender: %WinDir%\System32\config\Systemprofile\Application Data\62.exe
HKCU\Software\Microsoft\Active Setup\Installed Components\{58A4FBC3-BFD8-4CBC-CEF4-FD3BDF548BC9}\StubPath: %WinDir%\System32\config\Systemprofile\Application Data\62.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Defender: %WinDir%\System32\config\Systemprofile\Application Data\62.exe

Detected by UnHackMe:

62.EXE
Default location: %APPDATA%\62.EXE

Dropper information:
MD5: 9112009e7d9c5ff25ae978beb43e00f8
File size: 217424 bytes

Leave a Reply