Worm AMN – WaterMark.exe – 0bca859b3dafa375ec84ab4d07a29f5b

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Worm AMN
Also known as: Trojan ZBot, Trojan Siggen
SHA256: c29ddadbb206dd5f87ec2cffec24ee44e613333849de87eb020601bfccc3c44d
SHA1: 66f7332dbe2f77a19dfa98e0d35bf3eced393928
MD5: 0bca859b3dafa375ec84ab4d07a29f5b
File size: 135650 bytes

Created files:

%Program Files%\Microsoft\WaterMark.exe – Worm AMN
%Common AppData%\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\avcodec-53.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\avformat-53.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\avutil-51.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome_frame_helper.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome_frame_helper.exe – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome_launcher.exe – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\d3dcompiler_43.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\d3dx9_43.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\gcswf32.dll – Worm AMN

Worm AMN created autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: c:\windows\System32\userinit.exe,,c:\program files\Microsoft\watermark.exe

Leave a Reply