The file SEDQQW1A.EXE is a computer worm.
The worm SEDQQW1A.EXE is a self-replicating malicious program,
which uses a computer network to send copies of itself to other
computers.
You must fix the SEDQQW1A.EXE problem as soon as possible!
Delete the file SEDQQW1A.EXE from all infected computers in your network.
Set up your network firewall against SEDQQW1A.EXE intervention.
Malware Analysis of SEDQQW1A.EXE
Full path on a computer: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-41938475\sedqqw1a.exe
Detected by UnHackMe:
SEDQQW1A.EXE
Default location: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-41938475\sedqqw1a.exe
Removal Results: Success
Number of reboot: 1
SEDQQW1A.EXE is known as:
Worm.Hamweq, Trojan.Agent.VXGen, Worm.Hamweq.ppv, Trojan.Autoruner2.deakqv, Worm.Hamweq (A), HLLW.Autoruner2.1926, TR.Lethic.B.169, Worm.Hamweq.p.(kcloud), Trojan.Lethic.B, Worm.Ngrbot, Trj.Chgt.D, a variant of Win32.Injector.BKFA, Worm.Hamweq.Sxya, Trojan.Injector, Inject2.ASAB, Worm.Hamweq.AD
SEDQQW1A.EXE hash:
- MD5: c93c71ff9e57756457b3a03585a48a87
- HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman: “C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-41938475\sedqqw1a.exe”
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\sedqqw12: “C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-41938475\sedqqw1a.exe”
- HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: “explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-41938475\sedqqw1a.exe”
- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-41938475
- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-41938475\Desktop.ini
- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-41938475\sedqqw1a.exe