Home Malware Programs Worms W32/Banwarum

W32/Banwarum

Posted: August 28, 2007

Threat Metric

Threat Level: 9/10
Infected PCs: 30
First Seen: July 24, 2009
Last Seen: January 10, 2022
OS(es) Affected: Windows

W32/Banwarum is a mass mailing worm that spreads through email and network and infects Windows systems. The infected email has an attachment, which is infected with the worm. The extension of the infected attachment will be double. The first extension will be exe and second extension will be zip. W32/Banwarum may also come with gif image that contains password to extract zip file. Upon execution of the infected attachment, W32/Banwarum copies itself as mszsrn32.dll in Windows System folder. W32/Banwarum will inject dll code to winlogon.exe process to load itself during each startup.

W32/Banwarum

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



malware.exe File name: malware.exe
Size: 60.41 KB (60416 bytes)
MD5: c5a99a6399b06cf7c7519fd7d9fc710f
Detection count: 97
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
ealmukpk.dll File name: ealmukpk.dll
Size: 38.48 KB (38488 bytes)
MD5: e0d7da730f06985d6f2b50c540d64cc8
Detection count: 93
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
mszsrn32.dll File name: mszsrn32.dll
Size: 23.55 KB (23552 bytes)
MD5: c68b3bac3770e1b8a224fb1c78e4007f
Detection count: 83
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009

More files
Loading...