Solved! Use RUNDLL32MGR.EXE (Worm AMN) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

RUNDLL32MGR.EXE – Worm AMN removal

File MD5 Virus Alias
RUNDLL32MGR.EXE 28b2f587c7f293e4a23d59c4476409b3 Worm AMN
RUNDLL32MGR.EXE 28b2f587c7f293e4a23d59c4476409b3 Trojan SuspiciousFile
RUNDLL32MGR.EXE 28b2f587c7f293e4a23d59c4476409b3 Trojan XPACK
RUNDLL32MGR.EXE 28b2f587c7f293e4a23d59c4476409b3 Trojan Malware.Obscu
RUNDLL32MGR.EXE 28b2f587c7f293e4a23d59c4476409b3 Trojan Generic
RUNDLL32MGR.EXE 28b2f587c7f293e4a23d59c4476409b3 Trojan Eldorado

RUNDLL32MGR.EXE size: 123501 bytes
RUNDLL32MGR.EXE hash: 28B2F587C7F293E4A23D59C4476409B3

Created files:

%Program Files%\shmomfjs\bnebwisg.exe
%SysDir%\rundll32mgr.exe
%Common AppData%\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe
%Startup%\bnebwisg.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: %WinDir%\System32\userinit.exe,,%Program Files%\shmomfjs\bnebwisg.exe

Detected by UnHackMe:

RUNDLL32MGR.EXE
Default location: %SYSDIR%\RUNDLL32MGR.EXE

Dropper information:
MD5: 1ba6fd621ad0e4007a2f010b92c20421
File size: 242038 bytes

Leave a Reply