The file WINDI32.EXE can destroy your system, thus making the computer to work abnormally.
WINDI32.EXE is a dangerous file.
RemoveWINDI32.EXE from your computer immediately.
Kill the process WINDI32.EXE and remove WINDI32.EXE from the Windows startup.
Malware Analysis of WINDI32.EXE
Full path on a computer: %SysDir%\windi32.exe
Detected by UnHackMe:
WINDI32.EXE
Default location: %SysDir%\windi32.exe
Removal Results: Success
Number of reboot: 1
WINDI32.EXE is known as:
Trojan.Siggen, Obfuscated_FA, Trojan.Delf.UoAh6zK.Ln8, BehavesLike.Malware.ssc (mx-v), TR.Delf.OHS.8, Troj.Undef.(kcloud), Trojan.Agent.Gen-Autorun[Swisyn], W32.Trojan.AMST-4948, Trojan-Downloader.Delf, W32.Delf.OHS.tr
WINDI32.EXE hash:
- MD5: 54bbbf9679020a2c2356dec6d373deb9
How to quickly detect WINDI32.EXE presence?
Registry:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\LANDrivers: “%SysDir%\windi32.exe”
Files:
- %SysDir%\windi32.exe