I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
TIWI.SCR – Worm Brontok removal
File | MD5 | Virus Alias |
---|---|---|
TIWI.SCR | 601045551878fd20d29eb203a05b45e1 | Worm Brontok |
TIWI.SCR | 601045551878fd20d29eb203a05b45e1 | Trojan Eldorado |
TIWI.SCR | 601045551878fd20d29eb203a05b45e1 | Trojan Agent |
TIWI.SCR size: 87061 bytes
TIWI.SCR hash: 601045551878FD20D29EB203A05B45E1
Created files:
C:\tiwi.exe
%WinDir%\msvbvm60.dll
%SysDir%\IExplorer.exe
%SysDir%\msvbvm60.dll
%SysDir%\shell.exe
%SysDir%\tiwi.scr
%WinDir%\tiwi.exe
%Common Startmenu%\Programs\Startup\Empty.pif
%Local AppData%\WINDOWS\cute.exe
%Local AppData%\WINDOWS\imoet.exe
%Local AppData%\WINDOWS\lsass.exe
%Local AppData%\WINDOWS\smss.exe
%Local AppData%\WINDOWS\winlogon.exe
Autostart registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\LogonUSER: %Local AppData%\WINDOWS\imoet.exe
HKCU\Control Panel\Desktop\SCRNSAVE.EXE: %WinDir%\System32\tiwi.SCR
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\tiwi: %WinDir%\tiwi
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MSMSGS: %Local AppData%\WINDOWS\winlogon.exe
Detected by UnHackMe:
TIWI.SCR
Default location: %SYSDIR%\TIWI.SCR
Dropper information:
MD5: 040207916cd19ad77d263dcdb1f20a00
File size: 87061 bytes