Solved! Use GPHONE.EXE (Worm Autoit) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

GPHONE.EXE – Worm Autoit removal

File MD5 Virus Alias
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Worm Autoit
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Trojan Hllw
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Trojan Downloader
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Worm Sohanat
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Worm Autorun
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Trojan Agent

GPHONE.EXE size: 8781253 bytes
GPHONE.EXE hash: 494BBFB409FF1FF97C002A781F77F7D4

Created files:

%WinDir%\gphone.exe
%SysDir%\gphone.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe gphone.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Yahoo Messengger: %WinDir%\System32\gphone.exe

Detected by UnHackMe:

GPHONE.EXE
Default location: %WinDir%\GPHONE.EXE

Dropper information:
MD5: 494bbfb409ff1ff97c002a781f77f7d4
File size: 8781253 bytes

Leave a Reply