INETINFO.EXE – Worm Brontok

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

INETINFO.EXE – Worm Brontok removal

FileMD5Virus Alias
INETINFO.EXE 053dd269a3ed1ef44f0ab04599d5dffd Worm Brontok
INETINFO.EXE 053dd269a3ed1ef44f0ab04599d5dffd Worm AMN
INETINFO.EXE 053dd269a3ed1ef44f0ab04599d5dffd Trojan Agent

INETINFO.EXE size: 42089 bytes

Created files:

%WinDir%\eksplorasi.exe
%WinDir%\ShellNew\bronstab.exe
%Local AppData%\csrss.exe
%Local AppData%\inetinfo.exe
%Local AppData%\lsass.exe
%Local AppData%\services.exe
%Local AppData%\smss.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\run\Bron-Spizaetus: “%WinDir%\ShellNew\bronstab.exe”
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe “%WinDir%\eksplorasi.exe”
HKCU\Software\Microsoft\Windows\CurrentVersion\run\Tok-Cirrhatus: “%WinDir%\System32\config\Systemprofile\Local Settings\Application Data\smss.exe”

Detected by UnHackMe:

INETINFO.EXE
Default location: %LOCAL APPDATA%\INETINFO.EXE

Leave a Reply