msiexec32.exe - Dangerous
msiexec32.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
The Subject, Body, and Attachment name in the email vary.
Creates a copy of itself as %Windir%\Msiexec32.exe.
Creates the file, %Windir%\Winexec.exe.vbs, and executes it.
This file is detected as W32.Ainesey.A@mm!vbs.
Adds the values:
"MSIEXEC"="%Windows%\MSIEXEC32.exe"
"WinExec"=""%Windows%\Winexec.exe.vbs"
to the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
Searches local hard drives and network drives for files with the following extensions and overwrites them:
.vbs; .vbe; .js; .jse; .css; .wsh; .sct; .hta; .mp3; .wma
The worm appends a .vbs extension to .js, .jse, .css, .wsh, .sct, .hta, .mp3, and .wma files.
Adds the values to some registry keys which decreases security settings in Microsoft Word, Excel, and PowerPoint.
Emails a copy of itself to the email addresses gathered from the system.
Automatic removal: Use RegRun Startup Optimizer to remove it from startup.