Worm[Email]/Win32.Mamianune.lf

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

Worm[Email]/Win32.Mamianune.lf also known as W32/Worm.AHDL, W32/Mamianune.lf, Win32.Mamianune.A.

Malware Analysis of Worm[Email]/Win32.Mamianune.lf – ORPYWNDSAPOTCQ.EXE

Created files:

%Local Appdata%\Microsoft\CD Burning\sotgyllwkmwwui.htm
%Common Documents%\My Pictures\zdasm.htm
%Common Documents%\My Videos\wfgwvqku.htm
%WinDir%\Resources\emrupknqyn.htm
%SysDir%\orpywndsapotcq.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\q.exe: 43 3A 5C 57 49 4E 44 4F 57 53 5C 73 79 73 74 65 6D 33 32 5C 6F 72 70 79 77 6E 64 73 61 70 6F 74 63 71 2E 65 78 65 00 0C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Detected by UnHackMe:

ORPYWNDSAPOTCQ.EXE
Default location: %SYSDIR%\ORPYWNDSAPOTCQ.EXE

Dropper hash(md5): c5bae49e48bc31389188a0a1e003b960

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

4
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera