I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
Worm Pronny
Also known as: Trojan Crypt, Trojan Meredrop
SHA256: 44fe223aec866a580f2f91977f8d7b90eb64e83696b7f6c27cea07ec0896abdd
SHA1: 1218801f151a46f99014c015f3e35b33f4474754
MD5: d0c09fa954f4b633e40dae23d4c5e763
File size: 245760 bytes
Created files:
%SysDir%\macvzeuo.dll – Worm Pronny
%UserProfile%\1dqm.exe – Worm Pronny
%UserProfile%\3dqm.exe – Worm Pronny
%UserProfile%\4dqm.exe – Worm Pronny
%UserProfile%\5dqm.exe – Worm Pronny
%UserProfile%\duuday.com – Worm Pronny
%UserProfile%\gwbiuj.exe – Worm Pronny
%UserProfile%\start1.exe – Worm Pronny
%UserProfile%\yueino.exe – Worm Pronny
%UserProfile%\zdqm.exe – Worm Pronny
Worm Pronny created autostart registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\AutoStart: %UserProfile%\4dqm.exe
user\current_classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32\ThreadingModel: Both
user\current_classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32 : %Local AppData%\{ae229ccd-6a28-e4e8-8a47-3737ee4e0fed}\n.