Threat Database Trojans msiexec.exe

msiexec.exe

By Domesticus in Trojans

msiexec.exe is a malicious computer Trojan that covers itself as a legit executable file msiexec.exe that interprets packages and installs programs. Cyber crooks attempt to avoid anti-virus software detections and trick PC users by giving a malicious software tool the same name of some other legit tools. When you search on Google for the word 'msiexec.exe', you're introduced with a list of results saying that it's a legitimate Windows program. In this case, the file location of the malicious msiexec.exe program (C:\Users\[UserName]\msiexec.exe) clearly shows that msiexec.exe simulates to be something it's not. The malicious msiexec.exe downloads additional malware infections onto your computer. Even if you delete it manually, it may reappear after you restart your machine. That's why it is strongly advised scanning your computer with a reputable and trustworthy anti-spyware application.

File System Details

msiexec.exe creates the following file(s):
# File Name Detections
1. C:\Windows\System32\SYSTEM32\msorcl3232.exe N/A
2. C:\Windows\System32WINDIR%\SYSTEM32\avicap3232.dll N/A
3. C:\Windows\System32\mycomput32.exe N/A
4. msiexec.exe N/A
5. C:\Windows\System32\strmdll32.dll N/A
6. C:\Windows\System32\SYSTEM32\55274-640-2001945-237251270C.manifest N/A
7. %Temp%\2BA98D.dmp N/A
8. C:\Windows\System32\SYSTEM32\248321536 N/A
9. %Temp%\WER11.tmp N/A
10. C:\Windows\System32\SYSTEM32\55274-640-2001945-237251270P.manifest N/A
11. C:\Windows\System32\SYSTEM32\55274-640-2001945-237251270S.manifest N/A

Registry Details

msiexec.exe creates the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{167D8C11-D0F7-4D4A-94FF-1B727D3CFC51}\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{53FBF74C-ACD3-8E42-3397-A342CEE0B972}\INPROCSERVER32\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\IVEDHGVTFU\CLSID\
HKEY_USERS\.DEFAULT\SOFTWARE\IVEDHGVTFU\HKEY_USERS\.DEFAULT\SOFTWARE\IVEDHGVTFU\CLSID\
HKEY_CURRENT_USER\SOFTWARE\IVEDHGVTFU\CLSID\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\.FSHARPROJ\PERSISTENTHANDLER\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{53FBF74C-ACD3-8E42-3397-A342CEE0B972}\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\IVEDHGVTFU\
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{53FBF74C-ACD3-8E42-3397-A342CEE0B972}\
HKEY_CURRENT_USER\SOFTWARE\IVEDHGVTFU\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\.FSHARPROJ\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{167D8C11-D0F7-4D4A-94FF-1B727D3CFC51}\INPROCSERVER32\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{CA80A1DF-1993-458D-B1C5-8893EC9E5770}\
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{167D8C11-D0F7-4D4A-94FF-1B727D3CFC51}\
HKEY_CURRENT_USER\SOFTWARE\

Trending

Most Viewed

Loading...