worm.win32.folstart.a
worm.win32.folstart.a also known as Gen:Variant.Adware.Mplug.45, Adware.MultiPlug!1.A126-oGReBhAEMdH (cloud), a variant of Win32/Adware.MultiPlug.KU. Malware Analysis of worm.win32.folstart.a – ACB3C07E16512E787301508AF21CE05A.EXE Created files: %COMMON APPDATA%\{D1DA171A-427F-5C8F-D1DA-A171A4275C69}\ACB3C07E16512E787301508AF21CE05A.DAT %COMMON APPDATA%\{D1DA171A-427F-5C8F-D1DA-A171A4275C69}\ACB3C07E16512E787301508AF21CE05A.EXE %SYSDIR%\TASKS\BIDAILY SYNCHRONIZE TASK[PR] %WINDIR%\TASKS\BIDAILY SYNCHRONIZE TASK[PR].JOB Detected by UnHackMe: ACB3C07E16512E787301508AF21CE05A.EXE DEFAULT LOCATION: %COMMON APPDATA%\{D1DA171A-427F-5C8F-D1DA-A171A4275C69}\ACB3C07E16512E787301508AF21CE05A.EXE Dropper hash(md5): acb3c07e16512e787301508af21ce05a UnHackMe removes malware invisible for your antivirus! UnHackMe is compatible with most antivirus software. UnHackMe…