Solved! Use MSTEK32.EXE (Trojan Agent) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

MSTEK32.EXE – Trojan Agent removal

File MD5 Virus Alias
MSTEK32.EXE 9af3bb5b9d36f5c4d394bede4e3970ac Trojan Agent
MSTEK32.EXE 9af3bb5b9d36f5c4d394bede4e3970ac Trojan Small

MSTEK32.EXE size: 261789 bytes
MSTEK32.EXE hash: 9AF3BB5B9D36F5C4D394BEDE4E3970AC

Created files:

%WinDir%\svchost.exe
%SysDir%\concp32.exe
%SysDir%\explorer.exe
%SysDir%\mstek32.exe
%SysDir%\vcl32.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{E4883584-8B9A-11D5-EBA1-F78EEEEEE983}\StubPath: mstek32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VCL: vcl32.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VCL: vcl32.exe

Detected by UnHackMe:

MSTEK32.EXE
Default location: %SYSDIR%\MSTEK32.EXE

Dropper information:
MD5: a6739246866a66582269dc40b7daacc9
File size: 229351 bytes

Leave a Reply