I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
CROSSFIRE0.EXE – Worm Ainslot removal
File | MD5 | Virus Alias |
---|---|---|
CROSSFIRE0.EXE | 15a2b255ff4b5bf2be8042b9b87bd7b2 | Worm Ainslot |
CROSSFIRE0.EXE | 15a2b255ff4b5bf2be8042b9b87bd7b2 | Trojan CI |
CROSSFIRE0.EXE | 15a2b255ff4b5bf2be8042b9b87bd7b2 | Worm AMN |
CROSSFIRE0.EXE | 15a2b255ff4b5bf2be8042b9b87bd7b2 | Worm Autoit |
CROSSFIRE0.EXE | 15a2b255ff4b5bf2be8042b9b87bd7b2 | Backdoor Prosti |
CROSSFIRE0.EXE | 15a2b255ff4b5bf2be8042b9b87bd7b2 | Trojan Agent |
CROSSFIRE0.EXE size: 408173 bytes
Created files:
%AppData%\crossfire0.exe
%TEMP%\uckfkzq
Autostart registry keys:
HKLM\Software\Microsoft\Active Setup\Installed Components\{BE111E3C-AEEC-E2A0-C050-A9DCABA8DFFB}\StubPath: %WinDir%\System32\config\Systemprofile\Application Data\crossfire0.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\WindowsDefender: %WinDir%\System32\config\Systemprofile\Application Data\crossfire0.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WindowsDefender: %WinDir%\System32\config\Systemprofile\Application Data\crossfire0.exe
HKCU\Software\Microsoft\Active Setup\Installed Components\{BE111E3C-AEEC-E2A0-C050-A9DCABA8DFFB}\StubPath: %WinDir%\System32\config\Systemprofile\Application Data\crossfire0.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsDefender: %WinDir%\System32\config\Systemprofile\Application Data\crossfire0.exe
Detected by UnHackMe:
CROSSFIRE0.EXE
Default location: %APPDATA%\CROSSFIRE0.EXE