Home / Spyware Encyclopedia / Exploit.IMG-WMF << Back

Recommendation to Automatically remove Exploit.IMG-WMF


Our products can remove Exploit.IMG-WMF and thousands of other Virus and Spyware automatically and instantly.

Exploit.IMG-WMF Details


  • Category Exploit
  • Discovered 2/2/2009 11:36:40 AM
  • Modified 1/2/2024 10:34:44 AM
  • Threat Level High
  • Category Description
    Exploits use vulnerabilities in operating systems and applications to achieve the same result. Or in other words, this is a type of malware containing a piece of software, a chunk of data, or sequence of commands that take advantage of a bug, glitch or vulnerability in order to cause unintended or unanticipated behavior to occur on computer software. This frequently includes such things as gaining control of a computer system or allowing privilege escalation or a denial of service attack.

The following Files were created:
VALUEFILESIZECOMPANYNAMEVERSIONSIGNATUREDate
5814CBC8.EXE 9728  f7de44cd7c20595d292635816754c2c8 
371ECA05.EXE 9728  f2262fbe8b255a1fd4a9fc8c6cb94195 
804F322B.EXE 23552  eafcec274aca6af1b66b891a4f0f3201 
d8831712.exe 9728  e6a0aa91b2df11885396b4a6cf369b31 
7F85E86E.EXE 9728  e4fcfd28e9770853682083be1f94d8a2 
F7DF8883.EXE 9728  d9c435e7b3e8cf6803154eda811f89cc 
8E07D672.DLL 46080  cde5c023de78a57bb94b4d27ba9a190b 
ECFA18FD.EXE 106603  bdc0b7c5c14a14518f0ccfb92f56eb68 
178BF117.EXE 79360  b9ca33c748c087f20d44b513eb81cc67 
9E929786.EXE 106576  9909bdf7a067838da0535dfb7822e461 

The following Registry Entries were created:
..\Software\Microsoft\Windows NT\CurrentVersion\image file execution options\processsafe.exe\(Default)
..\Software\Microsoft\Windows NT\CurrentVersion\image file execution options\arswp.exe\(Default)
..\Software\Microsoft\Windows NT\CurrentVersion\image file execution options\ravstub.exe\(Default)
..\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DrvAnti.exe\(Default)
..\Software\Microsoft\\"WinId"\"{A2C3051D-ED7F-428C-A391-A28BDECC668D}"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Windows Workstation Disc"\"%WIN.SYS32%\xx.exe"
..\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RawCopy.exe\(Default)
..\Software\Microsoft\\"WinId"\"{D07D0198-48B3-42AB-AA6F-75EE0EA0CE1F}"
..\Software\Microsoft\\"WinId"\"{FF90D3C3-8411-4E74-A855-D12C15D7FED7}"
..\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qqdoctormain.exe\(Default)

Notice
Please note that the following information is not controlled or endorsed by Max Secure Software. They are captured automatically by tools in our malware Research Lab as a result of executing Spyware Files or browsing Internet in virtual environment. Please contact us if you find any information inappropriate for removal. All the work contained in this report is copyrighted and should not be copied without permission from Max Secure Antivirus. We do not recommend browsing or removing these entries on your own manually. We do not take any warranty against the use or result of the use of this information.

Home / Malware Encyclopedia << Back

Max Total Security can detect & quarantine this Malware