REGSVR.EXE – Worm Autoit

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

REGSVR.EXE – Worm Autoit removal

File MD5 Virus Alias
REGSVR.EXE 029d1265c17391685f1200741c5cea29 Worm Autoit
REGSVR.EXE 029d1265c17391685f1200741c5cea29 Trojan SuspiciousFile
REGSVR.EXE 029d1265c17391685f1200741c5cea29 Trojan Hllw
REGSVR.EXE 029d1265c17391685f1200741c5cea29 Trojan Downloader
REGSVR.EXE 029d1265c17391685f1200741c5cea29 Worm Sohanat
REGSVR.EXE 029d1265c17391685f1200741c5cea29 Worm Vobfus

REGSVR.EXE size: 1394650 bytes
REGSVR.EXE hash: 029D1265C17391685F1200741C5CEA29

Created files:

%WinDir%\regsvr.exe
%SysDir%\regsvr.exe
%SysDir%\svchost .exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe regsvr.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Msn Messsenger: %WinDir%\System32\regsvr.exe

Detected by UnHackMe:

REGSVR.EXE
Default location: %WinDir%\REGSVR.EXE

Dropper information:
MD5: 029d1265c17391685f1200741c5cea29
File size: 1394650 bytes

Leave a Reply