Worm Ainslot – smmrss.exe – f9977c93a066010201fdedc920d94900

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Worm Ainslot
Also known as: Trojan Jorik, Backdoor IRCBot
SHA256: c37a49bc863d287c9dfd275873cba0d194c3d2add3b0fb311521fc5aa98299cf
SHA1: 5934008e1e2216e2d6fa38334b8728abad2e3d56
MD5: f9977c93a066010201fdedc920d94900
File size: 256515 bytes

Created files:

%Temp%\smmrss.exe – Worm Ainslot

Worm Ainslot created autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{F6FA323A-3AFF-09BC-22ED-C1EFBCAED9AB}\StubPath: %Temp%\smmrss.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\ActiveX: %Temp%\smmrss.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ActiveX: %Temp%\smmrss.exe
HKCU\Software\Microsoft\Active Setup\Installed Components\{F6FA323A-3AFF-09BC-22ED-C1EFBCAED9AB}\StubPath: %Temp%\smmrss.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ActiveX: %Temp%\smmrss.exe

Leave a Reply