DNFBOX.EXE – Worm WhiteIce

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DNFBOX.EXE – Worm WhiteIce removal

FileMD5Virus Alias
DNFBOX.EXE 38e17ba7d4fc090adedefea404c9d92c Worm WhiteIce
DNFBOX.EXE 38e17ba7d4fc090adedefea404c9d92c Virus Part

DNFBOX.EXE size: 3661688 bytes
DNFBOX.EXE hash: 38E17BA7D4FC090ADEDEFEA404C9D92C

Created files:

%SysDir%\3A7A0844.sys
%TEMP%\Temp\9kwg.exe
%TEMP%\Temp\DNFBox.exe
%TEMP%\_ir_sf_temp_0\lua5.1.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Control\Keyboard Layouts\E0010409\Layout File: KBDUS.DLL
HKLM\System\CurrentControlSet\Control\Keyboard Layouts\E0010409\Layout Text: 175053C1
HKLM\System\CurrentControlSet\Services\3A7A0844\Type: 01000000
HKLM\System\CurrentControlSet\Services\3A7A0844\ImagePath: 730079007300740065006D00330032005C00330041003700410030003800340034002E007300790073000000
HKLM\System\CurrentControlSet\Services\3A7A0844\Group: 42006100730065000000

Detected by UnHackMe:

DNFBOX.EXE
Default location: %TEMP%\TEMP\DNFBOX.EXE

Dropper information:
MD5: ab195a920cd6fb404d8def55a072d33f
File size: 3612672 bytes

Leave a Reply