We received the file WINDOWSERVICENT.EXE and detected that WINDOWSERVICENT.EXE is not good.
WINDOWSERVICENT.EXE is Adware. You should remove the file WINDOWSERVICENT.EXE.
Kill the process WINDOWSERVICENT.EXE and remove WINDOWSERVICENT.EXE from Windows.
Malware Analysis of WINDOWSERVICENT.EXE
Full path on a computer: %SysDir%\WindowServiceNT.exe
Detected by UnHackMe:
WINDOWSERVICENT.EXE
Default location: %SysDir%\WindowServiceNT.exe
Removal Results: Success
Number of reboot: 1
WINDOWSERVICENT.EXE is known as:
Adware.MicrowinSearch.A.4, AdWare.MicrowinSearch, Adware.MicrowinSearch, PUP.MyLinks, BScope.Trojan.Banker, Win32.Adware.MicrowinSearch, unknown virus Win32.DH{ICQiJQ8}
WINDOWSERVICENT.EXE hash:
- MD5: 1ecbe1935c6fabad7c6b73961c5eaf37
How to quickly detect WINDOWSERVICENT.EXE presence?
Registry:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MicrowindowSearch: “%SysDir%\MicrowindowSearch\MicrowindowSearch.exe”
- HKLM\System\CurrentControlSet\Services\ApplicationSpecialManagement\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
- HKLM\System\CurrentControlSet\Services\ApplicationSpecialManagement\ImagePath: “%SysDir%\WindowServiceNT.exe”
- HKLM\System\CurrentControlSet\Services\ApplicationSpecialManagement\DisplayName: “Application Special Management”
- HKLM\System\CurrentControlSet\Services\ApplicationSpecialManagement\ObjectName: “LocalSystem”
Folders:
- %Temp%\is-476PR.tmp
- %Temp%\is-476PR.tmp\_isetup
- %Temp%\is-N68UD.tmp
- %SysDir%\MicrowindowSearch
Files:
- %Temp%\is-476PR.tmp\_isetup\_RegDLL.tmp
- %Temp%\is-476PR.tmp\_isetup\_shfoldr.dll
- %Temp%\is-N68UD.tmp\MicrowindowSearch_setup_07.tmp
- %Program Files%\del_bat.cmd
- %Program Files%\MicrowindowSearch_setup_07.exe
- %SysDir%\MicrowindowSearch\FreeApp.exe
- %SysDir%\MicrowindowSearch\MicrowindowSearch.dat
- %SysDir%\MicrowindowSearch\MicrowindowSearch.exe
- %SysDir%\MicrowindowSearch\unins000.dat
- %SysDir%\MicrowindowSearch\unins000.exe
- %SysDir%\WindowServiceNT.exe