WRDRIVE32.EXE is Worm Kolab

June 27, 2012 by NightWatcher
Filed under: Worm 
: Solved!

Fix it immediately:

The file WRDRIVE32.EXE is malware related.
You must delete the file WRDRIVE32.EXE immediately!
Delete the file WRDRIVE32.EXE without delay!
Kill the process WRDRIVE32.EXE and remove WRDRIVE32.EXE from the Windows startup.

Malware Analysis of WRDRIVE32.EXE
Full path on a computer: %Windir%\wrdrive32.exe

Detected by UnHackMe:

WRDRIVE32.EXE
Default location: %Windir%\wrdrive32.exe

Removal Results: Success
Number of reboot: 1

WRDRIVE32.EXE is known as:

Worm.Kolab, Backdoor.Rbot

WRDRIVE32.EXE hash:

  • MD5: f5aff7fc71b1ca90d54f31b863f7ef60
How to quickly detect WRDRIVE32.EXE presence?

Registry:
  • HLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Microsoft Driver Setup = “%Windir%\wrdrive32.exe”
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Driver Setup: “%Windir%\wrdrive32.exe”
Files:
  • %Windir%\wrdrive32.exe

  • Recommended: UnHackMe anti-rootkit and anti-malware

    Premium software: RegRun Security Suite (Good choice for removal and protection)

    Written by

    Malware Hunter.

    Comments

    Tell me what you're thinking...
    and oh, if you want a pic to show with your comment, go get a gravatar!

    You must be logged in to post a comment.