Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

WINDOWSERVICENT.EXE is Adware MicrowinSearch.A.4

$
0
0

We received the file WINDOWSERVICENT.EXE and detected that WINDOWSERVICENT.EXE is not good.
WINDOWSERVICENT.EXE is Adware. You should remove the file WINDOWSERVICENT.EXE.
Kill the process WINDOWSERVICENT.EXE and remove WINDOWSERVICENT.EXE from Windows.

Malware Analysis of WINDOWSERVICENT.EXE
Full path on a computer: %SysDir%\WindowServiceNT.exe

Detected by UnHackMe:

WINDOWSERVICENT.EXE
Default location: %SysDir%\WindowServiceNT.exe

Removal Results: Success
Number of reboot: 1

WINDOWSERVICENT.EXE is known as:

Adware.MicrowinSearch.A.4, AdWare.MicrowinSearch, Adware.MicrowinSearch, PUP.MyLinks, BScope.Trojan.Banker, Win32.Adware.MicrowinSearch, unknown virus Win32.DH{ICQiJQ8}

WINDOWSERVICENT.EXE hash:

  • MD5: 1ecbe1935c6fabad7c6b73961c5eaf37
How to quickly detect WINDOWSERVICENT.EXE presence?
Registry:
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MicrowindowSearch: “%SysDir%\MicrowindowSearch\MicrowindowSearch.exe”
  • HKLM\System\CurrentControlSet\Services\ApplicationSpecialManagement\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
  • HKLM\System\CurrentControlSet\Services\ApplicationSpecialManagement\ImagePath: “%SysDir%\WindowServiceNT.exe”
  • HKLM\System\CurrentControlSet\Services\ApplicationSpecialManagement\DisplayName: “Application Special Management”
  • HKLM\System\CurrentControlSet\Services\ApplicationSpecialManagement\ObjectName: “LocalSystem”
Folders:
  • %Temp%\is-476PR.tmp
  • %Temp%\is-476PR.tmp\_isetup
  • %Temp%\is-N68UD.tmp
  • %SysDir%\MicrowindowSearch
Files:
  • %Temp%\is-476PR.tmp\_isetup\_RegDLL.tmp
  • %Temp%\is-476PR.tmp\_isetup\_shfoldr.dll
  • %Temp%\is-N68UD.tmp\MicrowindowSearch_setup_07.tmp
  • %Program Files%\del_bat.cmd
  • %Program Files%\MicrowindowSearch_setup_07.exe
  • %SysDir%\MicrowindowSearch\FreeApp.exe
  • %SysDir%\MicrowindowSearch\MicrowindowSearch.dat
  • %SysDir%\MicrowindowSearch\MicrowindowSearch.exe
  • %SysDir%\MicrowindowSearch\unins000.dat
  • %SysDir%\MicrowindowSearch\unins000.exe
  • %SysDir%\WindowServiceNT.exe


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>