Home Malware Programs Worms W32/Banwarum

W32/Banwarum

Posted: August 28, 2007

Threat Metric

Threat Level: 9/10
Infected PCs: 30
First Seen: July 24, 2009
Last Seen: January 10, 2022
OS(es) Affected: Windows

W32/Banwarum is a mass mailing worm that spreads through email and network and infects Windows systems. The infected email has an attachment, which is infected with the worm. The extension of the infected attachment will be double. The first extension will be exe and second extension will be zip. W32/Banwarum may also come with gif image that contains password to extract zip file. Upon execution of the infected attachment, W32/Banwarum copies itself as mszsrn32.dll in Windows System folder. W32/Banwarum will inject dll code to winlogon.exe process to load itself during each startup.

W32/Banwarum

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



ealmukpk.dll File name: ealmukpk.dll
Size: 38.48 KB (38488 bytes)
MD5: e0d7da730f06985d6f2b50c540d64cc8
Detection count: 93
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
malware.exe File name: malware.exe
Size: 31.23 KB (31232 bytes)
MD5: 63d114a71ae576c34e03cddf57613de8
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
mszsrn32.dll File name: mszsrn32.dll
Size: 23.55 KB (23552 bytes)
MD5: c68b3bac3770e1b8a224fb1c78e4007f
Detection count: 83
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
Loading...