FACEBOOKAUTOUPDATER.EXE – Worm Ainslot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

FACEBOOKAUTOUPDATER.EXE – Worm Ainslot removal

FileMD5Virus Alias
FACEBOOKAUTOUPDATER.EXE bebb77cba8af33bdd3182391651d8042 Worm Ainslot
FACEBOOKAUTOUPDATER.EXE bebb77cba8af33bdd3182391651d8042 Backdoor Blackshades
FACEBOOKAUTOUPDATER.EXE bebb77cba8af33bdd3182391651d8042 Backdoor Maximus
FACEBOOKAUTOUPDATER.EXE bebb77cba8af33bdd3182391651d8042 Trojan Agent
FACEBOOKAUTOUPDATER.EXE bebb77cba8af33bdd3182391651d8042 Trojan Swisyn
FACEBOOKAUTOUPDATER.EXE bebb77cba8af33bdd3182391651d8042 Trojan FakeAV

FACEBOOKAUTOUPDATER.EXE size: 466944 bytes
FACEBOOKAUTOUPDATER.EXE hash: BEBB77CBA8AF33BDD3182391651D8042

Created files:

%AppData%\FaceBookAutoUpdater.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{3F21A8E8-C475-C713-B7BD-EA31DBECB664}\StubPath: %WinDir%\System32\config\Systemprofile\Application Data\FaceBookAutoUpdater.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\svchost.exe: %WinDir%\System32\config\Systemprofile\Application Data\FaceBookAutoUpdater.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\svchost.exe: %WinDir%\System32\config\Systemprofile\Application Data\FaceBookAutoUpdater.exe
HKCU\Software\Microsoft\Active Setup\Installed Components\{3F21A8E8-C475-C713-B7BD-EA31DBECB664}\StubPath: %WinDir%\System32\config\Systemprofile\Application Data\FaceBookAutoUpdater.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost.exe: %WinDir%\System32\config\Systemprofile\Application Data\FaceBookAutoUpdater.exe

Detected by UnHackMe:

FACEBOOKAUTOUPDATER.EXE
Default location: %APPDATA%\FACEBOOKAUTOUPDATER.EXE

Dropper information:
MD5: bebb77cba8af33bdd3182391651d8042
File size: 466944 bytes

Leave a Reply