Solved! Use WINWORD2.DOC.EXE (Worm Autoit) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

WINWORD2.DOC.EXE – Worm Autoit removal

File MD5 Virus Alias
WINWORD2.DOC.EXE e83f340f22b6626f9c3d20ce59a88cbe Worm Autoit
WINWORD2.DOC.EXE e83f340f22b6626f9c3d20ce59a88cbe Backdoor Bredolab
WINWORD2.DOC.EXE e83f340f22b6626f9c3d20ce59a88cbe Trojan Generic
WINWORD2.DOC.EXE e83f340f22b6626f9c3d20ce59a88cbe Trojan Runner
WINWORD2.DOC.EXE e83f340f22b6626f9c3d20ce59a88cbe Trojan Downloader
WINWORD2.DOC.EXE e83f340f22b6626f9c3d20ce59a88cbe Worm Sohanat

WINWORD2.DOC.EXE size: 261731 bytes
WINWORD2.DOC.EXE hash: E83F340F22B6626F9C3D20CE59A88CBE

Created files:

C:\Documents and Settings\Default User\Templates\winword.doc.exe
C:\Documents and Settings\Default User\Templates\winword.nal
C:\Documents and Settings\Default User\Templates\winword2.doc.exe
C:\Documents and Settings\Default User\Templates\winword2.nal
%SysDir%\driizbmv.exe
%SysDir%\msvbvm50.900
%SysDir%\msvbvm60.491
%SysDir%\ooywllhtot.exe
%SysDir%\pckhar.exe
%SysDir%\xqfmljohaznwr.exe
%SysDir%\xuldvjgzzlifkbd.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\luxewpxk: ooywllhtot.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\fjzpqtkf: xuldvjgzzlifkbd.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run : xqfmljohaznwr.exe
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname: VirusBenci
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\NV Hostname: VirusBenci

Detected by UnHackMe:

WINWORD2.DOC.EXE
Default location: C:\DOCUMENTS AND SETTINGS\DEFAULT USER\TEMPLATES\WINWORD2.DOC.EXE

Dropper information:
MD5: 18bee1f435828d5aa5d8f6f7ce81d84e
File size: 261699 bytes

Leave a Reply