I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
CMD-BRONTOK.EXE – Worm Brontok removal
File | MD5 | Virus Alias |
---|---|---|
CMD-BRONTOK.EXE | ef254efd3da13ddbdb2bd4230ee8eed0 | Worm Brontok |
CMD-BRONTOK.EXE | ef254efd3da13ddbdb2bd4230ee8eed0 | Trojan SuspiciousFile |
CMD-BRONTOK.EXE | ef254efd3da13ddbdb2bd4230ee8eed0 | Trojan Eldorado |
CMD-BRONTOK.EXE | ef254efd3da13ddbdb2bd4230ee8eed0 | Trojan Krap |
CMD-BRONTOK.EXE | ef254efd3da13ddbdb2bd4230ee8eed0 | Trojan Agent |
CMD-BRONTOK.EXE size: 133120 bytes
CMD-BRONTOK.EXE hash: EF254EFD3DA13DDBDB2BD4230EE8EED0
Created files:
%WinDir%\KesenjanganSosial.exe
%WinDir%\ShellNew\RakyatKelaparan.exe
%SysDir%\cmd-brontok.exe
%Local AppData%\br5205on.exe
%Local AppData%\csrss.exe
%Local AppData%\inetinfo.exe
%Local AppData%\lsass.exe
%Local AppData%\services.exe
%Local AppData%\smss.exe
%Local AppData%\svchost.exe
%Local AppData%\winlogon.exe
%SysDir%\msvbvm60.dll
Autostart registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\run\Bron-Spizaetus: “%WinDir%\ShellNew\RakyatKelaparan.exe”
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe “%WinDir%\KesenjanganSosial.exe”
HKCU\Software\Microsoft\Windows\CurrentVersion\run\Tok-Cirrhatus-2091: “%WinDir%\System32\config\Systemprofile\Local Settings\Application Data\br5205on.exe”
Detected by UnHackMe:
CMD-BRONTOK.EXE
Default location: %SYSDIR%\CMD-BRONTOK.EXE
Dropper information:
MD5: ef254efd3da13ddbdb2bd4230ee8eed0
File size: 133120 bytes