WIN.EXE – Worm Autorun

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

WIN.EXE – Worm Autorun removal

FileMD5Virus Alias
WIN.EXE 00abc440f28c36dd5239f0f0957a2d8c Worm Autorun
WIN.EXE 00abc440f28c36dd5239f0f0957a2d8c Trojan Generic
WIN.EXE 00abc440f28c36dd5239f0f0957a2d8c Trojan Hllw

WIN.EXE size: 273920 bytes
WIN.EXE hash: 00ABC440F28C36DD5239F0F0957A2D8C

Created files:

%WinDir%\Large\win.exe
%TEMP%\GRY-XX-X
%TEMP%\uU-GRY-Xx

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{MB3JKSW-Y883-WE0K-IY6U-SL6N6I178}\StubPath: 43003A005C00570049004E0044004F00570053005C004C0061007200670065005C00770069006E002E006500780065000000
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: 43003A005C00570049004E0044004F00570053005C004C0061007200670065005C00770069006E002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: 43003A005C00570049004E0044004F00570053005C004C0061007200670065005C00770069006E002E006500780065000000

Detected by UnHackMe:

WIN.EXE
Default location: %WinDir%\LARGE\WIN.EXE

Dropper information:
MD5: 00abc440f28c36dd5239f0f0957a2d8c
File size: 273920 bytes

Leave a Reply