Malremtool.exe

Malremtool.exe Description

Malremtool.exe is an unsafe executable file connected with the fake security programs Master Utilities and System Recovery. Malremtool.exe may be distributed via infected links, malicious websites, spam email attachments and corrupt files downloaded from the Internet. Malremtool.exe comes bundled with a botnet Trojan, fake codecs, bogus flash or other malicious program upgrades. Malremtool.exe can spread via the network and attempts to make copies of itself across the existing system files or computer drivers. Malremtool.exe is a group of Internet robots, or bots that run automatically on corrupted machine when the malware file is opened. Malremtool.exe makes the drives on the attacked PC unbootable. Malremtool.exe conceals shortcuts and programs on your Start menu. Malremtool.exe also displays security alerts and critical hard disk drive error messages. You should remove Malremtool.exe as soon as possible.

Technical Information

File System Details

Malremtool.exe creates the following file(s):
# File Name Detection Count
1 %Documents and Settings%\[User Name]\Local Settings\Application Data\[RANDOM CHARACTERS].exe N/A
2 %Documents and Settings%\[User Name]\Local Settings\Temp\smtmp\ N/A
3 %Documents and Settings%\[User Name]\Start Menu\\Programs\malremtool\ N/A
4 %Documents and Settings%\[User Name]\Desktop\malremtoollnk N/A
5 %Documents and Settings%\[User Name]\Local Settings\Application Data\~ N/A
6 %Documents and Settings%\[User Name]\Start Menu\\Programs\malremtool\Uninstall malremtool.lnk N/A
7 %Documents and Settings%\[User Name]\Local Settings\Application Data\[RANDOM CHARACTERS] N/A
8 %Documents and Settings%\[User Name]\Start Menu\\Programs\malremtool\malremtool.lnk N/A

Registry Details

Malremtool.exe creates the following registry entry or registry entries:
RegistryKey
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU "MRUList"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"

One Comment

  • Remove Malremtool.exe:

    Thank you sooo much…..u saved me the trouble and time of taking my pc to the store……thnks a million….all ur steps work and did fix my problem!!