SYSINF0.EXE – Worm Autorun

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SYSINF0.EXE – Worm Autorun removal

File MD5 Virus Alias
SYSINF0.EXE 0842d7c8422000368b55a10915e84695 Worm Autorun
SYSINF0.EXE 0842d7c8422000368b55a10915e84695 Trojan Downloader
SYSINF0.EXE 0842d7c8422000368b55a10915e84695 Trojan Agent
SYSINF0.EXE 0842d7c8422000368b55a10915e84695 Trojan Scar

SYSINF0.EXE size: 61440 bytes
SYSINF0.EXE hash: 0842D7C8422000368B55A10915E84695

Created files:

%SysDir%\SYSINF0.exe
D:\32Bit .exe
D:\No Delete .exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Start: 02000000
HKLM\System\CurrentControlSet\Services\Type: 20000000
HKLM\System\CurrentControlSet\Services\Wnetwiss\Type: 10010000
HKLM\System\CurrentControlSet\Services\Wnetwiss\Start: 02000000
HKLM\System\CurrentControlSet\Services\Wnetwiss\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Wnetwiss\DisplayName: Windows netware work information System setup
HKLM\System\CurrentControlSet\Services\Wnetwiss\ImagePath: %WinDir%\System32\SYSINF0.exe

Detected by UnHackMe:

SYSINF0.EXE
Default location: %SYSDIR%\SYSINF0.EXE

Dropper information:
MD5: 0842d7c8422000368b55a10915e84695
File size: 61440 bytes

Leave a Reply