a variant of Win32/Amonetize.AL

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

a variant of Win32/Amonetize.AL also known as Adware.Win32.Amonetize.AL, Gen:Variant.Graftor.137063, WS.Reputation.1.

Malware Analysis of a variant of Win32/Amonetize.AL

Created files:

%Temp%\tmp6.exe
%Temp%\tmp6.tmp
%Temp%\tmp8\Bundle.exe
%Temp%\tmp8.tmp
%Temp%\tmpB.tmp

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8F986292-C5AD-4831-9501-88F5A9DCCB0C}_is1\DisplayName: “YouTubeMP3Converter version 1.2.0.0”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8F986292-C5AD-4831-9501-88F5A9DCCB0C}_is1\UninstallString: “”%Local Appdata%\YouTubeMP3Converter\unins000.exe””
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9AAF2503-6CD5-414A-B5BA-37639B76C91F}\DisplayName: “YouTubeMP3Converter”
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9AAF2503-6CD5-414A-B5BA-37639B76C91F}\UninstallString: “”%Appdata%\YouTubeMP3Converter\youtubemp3converterinst.exe” –uninstall”

Detected by UnHackMe:

BUNDLE.EXE
Default location: %TEMP%\TMP8\BUNDLE.EXE

Dropper hash(md5): e914d948336a04463eca9fce9c87ef20

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

1
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera