Worm Ainslot – T0NOLRQ1DJ.exe – 2568729e9e4c7f40ba8aa8cde6739df7

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Worm Ainslot
Also known as: Backdoor Blackshades, Trojan Jorik
SHA256: fe3cff62e1478c734421271df7a7f042e86ab0b6f69c3e45b4bcc92af0be0b74
SHA1: f9c3494e8d136ad45d9d6d884e0e600dfa0a2f27
MD5: 2568729e9e4c7f40ba8aa8cde6739df7
File size: 505768 bytes

Created files:

%AppData%\T0NOLRQ1DJ.exe – Worm Ainslot

Worm Ainslot created autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{B731FFEE-1EB6-4DAD-D2D5-EEAA2F6BFFCF}\StubPath: %AppData%\T0NOLRQ1DJ.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\Windows Defender: %AppData%\T0NOLRQ1DJ.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Defender: %AppData%\T0NOLRQ1DJ.exe
HKCU\Software\Microsoft\Active Setup\Installed Components\{B731FFEE-1EB6-4DAD-D2D5-EEAA2F6BFFCF}\StubPath: %AppData%\T0NOLRQ1DJ.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Defender: %AppData%\T0NOLRQ1DJ.exe

Leave a Reply