av_md.exe was added to FreeFixer's database on 7th December 2009. The most recent search for this file was done on 20th December 2009. av_md.exe is usually located in the 'C:\Users\OmarC\' folder and has a size of 27477 bytes.
Please note that the location of the file can vary. A list of the most common folder variants are listed ahead in this document.
So far there have been 4 searches for av_md.exe.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
av_md.exe is not signed.
| Property | Value |
|---|---|
| MD5 | 71a20dac02a5483b13ef787982****** |
| SHA256 | 53fa9b77b7188dbb346b5507b0f86ff2a1dc86c20ac2bb9b14b051da36****** |
av_md.exe may also be located in other folders than C:\Users\OmarC\. The most common variants are listed below:
To help other users, please let us know what you will do with av_md.exe:
The poll result listed below shows what other users chose to do with av_md.exe:
NOTE: Please do not use this poll as the only source of input to determine what you will do with av_md.exe.
If you feel that you need more information to determine if your should keep this file or remove it, please read this guide.
Hi, my name is Roger Karlsson. I've been running this website since 2006. I want to let you know about the FreeFixer program. FreeFixer is a freeware tool that analyzes your system and let you manually identify unwanted programs. Once you've identified some malware files, FreeFixer is pretty good at removing them. You can download FreeFixer here. It runs on Windows 2000/XP/2003/20008/Vista/7 RC1. (32-bit only).
If you have questions, feedback on FreeFixer or the freefixer.com website, need help analyzing FreeFixer's scan result or just want to say hello, please contact me. You can find my email address at the contact page.
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
Besides modifying the atapi.sys driver it also sets up several files in Startup\Run\. I have several computers infected with this virus.
Files I've found are: siszyd32.exe (Startup\Run) and other similar files. Also, has hidden background processes or sometimes opens files like ~TMP.tmp or smth like that.
Sugessted was kaspersky virus removal tool which I'm using right now, and waiting for it to finish.
# 8 Dec 2009, 6:23
I have found the av_md.exe through the process explorer. I believe it sets up a new user account in svchost.exe 1048 on XP. This for me entailed the DCOM Server Process Launcher(system32\rpcss.dll) and Terminal Services (system32\termsrv.dll).
I believe that it will attach to a mail program on the computer and send out spam for "weightloss" products. Symantec stopped these from being sent.
Looking to remove it now.
# 10 Dec 2009, 17:22
how we remove this ? some times it goes 99% cpu usage and freezes my pc
# 11 Dec 2009, 8:20
It also replaces original regedit.exe ant starts it on startup
# 13 Dec 2009, 3:35
sshnas21.dll,
monnwb32,
monnid32,
wwwpos32.exe,
aqlb.hjo,
incognito.exe,
rarype32.exe,
netuza32.exe,
9fo3ar0j.exe,
kbdsock.dll,
freddy84.exe,
freddy82.exe,
freddy81.exe,
freddy80.exe,
extrac64_cab.exe,
wmpscfgs .exe,
cliconfg64.exe,
winhlp64.exe,
siszyd32.exe,
sshnas.dll,
IS2010.exe,
smss32.exe,
winlogon32.exe,
helper32.dll,
IS15.exe,
richtx64.exe,
settdebugx.exe,
sr882388.exe,
questservice111.exe,
ccdrive32.exe,
av_md.exe,
essledv.exe,
msa.exe,
algqeh32.exe,
ld16.exe,
freddy79.exe,
photo_id.exe,
winupdate86.exe,
kwanzy131.exe,
wind7upd.exe,
mstre26.exe,
winlogon86.exe,
AVR10.exe,
webserver.exe,
ihaupd32.exe,
wyeke.exe,
wyeke.dll,
AdobeARM.exe,
WLIDSVC.EXE,
ssscheduler.exe,
getPlus_Helper.dll,
wscsvc32.exe,
zavupd32.exe,
herss.exe,
ie3sh.exe,
pp14.exe,
zwangi.exe,
msb.exe
filterpipeline..,
Roger Karlsson writes