RFMUWFD.DLL – Trojan Kazy

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

RFMUWFD.DLL – Trojan Kazy removal

File MD5 Virus Alias
RFMUWFD.DLL 056d33909dc421dfde5a4a810e35e0d7 Trojan Kazy
RFMUWFD.DLL 056d33909dc421dfde5a4a810e35e0d7 Trojan SuspiciousFile
RFMUWFD.DLL 056d33909dc421dfde5a4a810e35e0d7 Trojan Artemis
RFMUWFD.DLL 056d33909dc421dfde5a4a810e35e0d7 Trojan OnLineGames
RFMUWFD.DLL 056d33909dc421dfde5a4a810e35e0d7 Trojan Agent

RFMUWFD.DLL size: 81920 bytes
RFMUWFD.DLL hash: 056D33909DC421DFDE5A4A810E35E0D7

Created files:

%SysDir%\Rfmuwfd.dll
%Common AppData%\Microsoft\Dr Watson\user.dmp

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\MediagCenterm\Type: 10000000
HKLM\System\CurrentControlSet\Services\MediagCenterm\Start: 02000000
HKLM\System\CurrentControlSet\Services\MediagCenterm\DisplayName: MS Mediai Controle Centern
HKLM\System\CurrentControlSet\Services\MediagCenterm\ImagePath: %SystemRoot%\System32\svchost.exe -k krnlsrvc
HKLM\System\CurrentControlSet\Services\MediagCenterm\Description: Providesi supportm for media palyerj. This service can’t be stoped

Detected by UnHackMe:

RFMUWFD.DLL
Default location: %SYSDIR%\RFMUWFD.DLL

Dropper information:
MD5: bbeb7b39b45dfdf8261fce8900b7145f
File size: 122880 bytes

Leave a Reply