Worm Brontok – esoJray.exe – b3c835e4c154dccc9c1f57f62d66b5fa

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Worm Brontok
Also known as: Trojan Agent, Worm Autorun
SHA256: 639580d23f6e2d68cbe5c9fa97eae31ba91b8859dc72b6f53f235a9ad539979e
SHA1: ae2c835641f6053f4894ae44aef2df519d6ff525
MD5: b3c835e4c154dccc9c1f57f62d66b5fa
File size: 81920 bytes

Created files:

%WinDir%\INF\esoJray.exe – Worm Brontok
%SysDir%\config\systemprofile\Local Settings\Application Data\csrss.exe – Worm Brontok
%SysDir%\config\systemprofile\Local Settings\Application Data\inetinfo.exe – Worm Brontok
%SysDir%\config\systemprofile\Local Settings\Application Data\lsass.exe – Worm Brontok
%SysDir%\config\systemprofile\Local Settings\Application Data\services.exe – Worm Brontok
%SysDir%\config\systemprofile\Local Settings\Application Data\smss.exe – Worm Brontok
%SysDir%\config\systemprofile\Local Settings\Application Data\winlogon.exe – Worm Brontok

Worm Brontok created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\run\Joseray_World : “%WinDir%\INF\esoJray.exe”
HKCU\Software\Microsoft\Windows\CurrentVersion\run\Andrian-PKus : “%WinDir%\System32\config\Systemprofile\Local Settings\Application Data\smss.exe”

Leave a Reply