SERVERX.EXE is Virus Madang

June 28, 2012 by NightWatcher
Filed under: Virus 
: Solved!

Fix it immediately:

We checked up the file SERVERX.EXE and found it hazardous.
The file SERVERX.EXE must be deleted from the system immediately.
Kill the process SERVERX.EXE and remove SERVERX.EXE from the Windows startup.

Malware Analysis of SERVERX.EXE
Full path on a computer: %SysDir%\Serverx.exe

Detected by UnHackMe:

Item Name: shell
Author: Unknown
Related File: Explorer.exe IEXPLOREi.exe
Type: System.ini

Item Name: Serverx
Author: Unknown
Related File: %SYSDIR%\SERVERX.EXE
Type: Registry Run

Item Name: Yahoo Messengger
Author: Unknown
Related File: %SYSDIR%\IEXPLOREI.EXE
Type: Registry Run

Item Name: At2
Author: Unknown
Related File: %SYSDIR%\WORD.EXE
Type: Scheduled Tasks

Item Name: At1
Author: Unknown
Related File: %SYSDIR%\WORD.EXE
Type: Scheduled Tasks

Item Name: Serverx.exe
Author: Unknown
Related File: %SYSDIR%\SERVERX.EXE
Type: Detected using Heuristic Algorithm

Item Name: IEXPLOREi.exe
Author: Unknown
Related File: %SYSDIR%\IEXPLOREI.EXE
Type: Running Processes

Removal Results: Success
Number of reboot: 1

SERVERX.EXE is known as:

Virus.Madang

SERVERX.EXE hash:

  • MD5: 0a37157e893c96a68dae505e42c19459
The file tries to download information from some web sites.
How to quickly detect SERVERX.EXE presence?

Registry:
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Yahoo Messengger: “%SysDir%\IEXPLOREi.exe”
  • HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: “Explorer.exe IEXPLOREi.exe”
Files:
  • %SysDir%\autorun.ini
  • %SysDir%\IEXPLOREi.exe
  • %SysDir%\Serverx.exe
  • %SysDir%\setting.ini
  • %SysDir%\WORD.exe
  • %WinDir%\Tasks\At1.job
  • %WinDir%\Tasks\At2.job
  • %WinDir%\IEXPLOREi.exe

  • Recommended: UnHackMe anti-rootkit and anti-malware

    Premium software: RegRun Security Suite (Good choice for removal and protection)

    Written by

    Malware Hunter.

    Comments

    Tell me what you're thinking...
    and oh, if you want a pic to show with your comment, go get a gravatar!

    You must be logged in to post a comment.