setup30.exe - Dangerous
setup30.exe
Manual removal instructions:
Antivirus Report of setup30.exe:
setup30.exe
I-Worm.Atirus is a Win32 worm that spreads by sending itself via e-mail to the recipients in a victim's Outlook Address book.
Then, the worm suspends for 5 minutes, then launches one of its payloads depending on system time.
After executing the payload, the worm checks whether the following registry value is present:
HKLM\Software\Microsoft\Windows\CurrentVersion Install=1
If the value doesn't exist, the worm tries to send itself to the senders of messages that exist in MAPI default client's folders.
The subject of the message sent is "New antivirus tool", and the message also contains the attachment "Antivirus.exe" that is the virus itself,
and also contains in the body: Hey, checkout this new antivirus tool which checks your system for viruses
Use RegRun Startup Optimizer to quickly remove this virus.
setup30.exe | Malware |
setup30.exe | Dangerous |
setup30.exe | High Risk |
Then, the worm suspends for 5 minutes, then launches one of its payloads depending on system time.
After executing the payload, the worm checks whether the following registry value is present:
HKLM\Software\Microsoft\Windows\CurrentVersion Install=1
If the value doesn't exist, the worm tries to send itself to the senders of messages that exist in MAPI default client's folders.
The subject of the message sent is "New antivirus tool", and the message also contains the attachment "Antivirus.exe" that is the virus itself,
and also contains in the body: Hey, checkout this new antivirus tool which checks your system for viruses
Use RegRun Startup Optimizer to quickly remove this virus.
Dmitry Sokolov:
I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.
Since that time I work every day to fix the issues that antiviruses cannot.
If your antivirus have not helped you solve the problem, you should try UnHackMe.
We are a small company and you can ask me directly, if you have any questions.