Worm AMN – WaterMark.exe – 01d98c5be4ab988fcc137a44f01090ea

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Worm AMN
Also known as: Trojan Siggen, Trojan Zbot
SHA256: 0903947bf1392740bb411cd4662daf7713e04ef42cd627cd5cabb89f41395e87
SHA1: 2978954fe2bfb679a13227a7c9c42f785a8a9cd6
MD5: 01d98c5be4ab988fcc137a44f01090ea
File size: 946562 bytes

Created files:

%Program Files%\Microsoft\WaterMark.exe – Worm AMN
%Program Files%\Windows Media Player\wmpband.dll – Worm AMN
%SysDir%\wmp.dll – Worm AMN
%SysDir%\wmvcore.dll – Worm AMN
%Common AppData%\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\avcodec-53.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\avformat-53.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\avutil-51.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome_frame_helper.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome_frame_helper.exe – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome_launcher.exe – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\d3dcompiler_43.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\d3dx9_43.dll – Worm AMN
%Local AppData%\Google\Chrome\Application\17.0.963.56\gcswf32.dll – Worm AMN

Worm AMN created autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: c:\windows\System32\userinit.exe,,c:\program files\Microsoft\watermark.exe

Leave a Reply