REGSVR.EXE – Worm Autoit

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

REGSVR.EXE – Worm Autoit removal

File MD5 Virus Alias
REGSVR.EXE 1e5c1e142f4681ea5b65457e76479cb6 Worm Autoit
REGSVR.EXE 1e5c1e142f4681ea5b65457e76479cb6 Trojan SuspiciousFile
REGSVR.EXE 1e5c1e142f4681ea5b65457e76479cb6 Trojan Click
REGSVR.EXE 1e5c1e142f4681ea5b65457e76479cb6 Trojan Downloader
REGSVR.EXE 1e5c1e142f4681ea5b65457e76479cb6 Worm Sohanat
REGSVR.EXE 1e5c1e142f4681ea5b65457e76479cb6 Worm Autorun

REGSVR.EXE size: 646145 bytes
REGSVR.EXE hash: 1E5C1E142F4681EA5B65457E76479CB6

Created files:

%WinDir%\regsvr.exe
%SysDir%\28463\svchost.001
%SysDir%\regsvr.exe
%SysDir%\svchost .exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe regsvr.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Msn Messsenger: %WinDir%\System32\regsvr.exe

Detected by UnHackMe:

REGSVR.EXE
Default location: %WinDir%\REGSVR.EXE

Dropper information:
MD5: 1e5c1e142f4681ea5b65457e76479cb6
File size: 646145 bytes

Leave a Reply