W32.eHeur.Malware03

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

Malware Analysis of W32.eHeur.Malware03 – WSMHOOK.DLL

Created files:

%Program Files%\Wondershare\Filmora\wsCUDA.dll
%Program Files%\Wondershare\Filmora\WSDVDBuilder.dll
%Program Files%\Wondershare\Filmora\WSMHook.dll
%Program Files%\Wondershare\Filmora\WSMultiTagMgr.dll
%Program Files%\Wondershare\Filmora\WSPlayer.dll

Autostart registry keys:

HKLM\SOFTWARE\CLASSES\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}\LOCALSERVER32\: “%SYSTEMDRIVE%\PROGRA~1\COMMON~1\WONDER~1\WONDER~1\WSHELPER.EXE”
HKLM\Software\Classes\CLSID\{967B86E6-92E8-4A35-86C0-FEB187726802}\LocalServer32\: “”%Program Files%\Wondershare\Filmora\ImageHost.exe””
HKLM\Software\Classes\WVEFile\Shell\Open\Command\: “”%Program Files%\Wondershare\Filmora\Filmora.exe” “%1″”
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Wondershare Helper Compact.exe: “%Program Files Common%\Wondershare\Wondershare Helper Compact\WSHelper.exe”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wondershare Filmora_is1\DisplayName: “Wondershare Filmora(Build 7.8.0)”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wondershare Filmora_is1\UninstallString: “”%Program Files%\Wondershare\Filmora\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1\DisplayName: “Wondershare Helper Compact 2.5.2”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1\UninstallString: “”%Program Files Common%\Wondershare\Wondershare Helper Compact\unins000.exe””

Detected by UnHackMe:

WSMHOOK.DLL
Default location: %PROGRAM FILES%\WONDERSHARE\FILMORA\WSMHOOK.DLL

Dropper hash(md5): 0c64e5e3813624f6db67a9679885d308

Share This:

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

1
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera