Z6.EXE – Trojan Kazy

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

Z6.EXE – Trojan Kazy removal

File MD5 Virus Alias
Z6.EXE bed6c29bb5c1a288c838d3a1dd8bd1e8 Trojan Kazy
Z6.EXE bed6c29bb5c1a288c838d3a1dd8bd1e8 Suspicious File
Z6.EXE bed6c29bb5c1a288c838d3a1dd8bd1e8 Trojan Artemis
Z6.EXE bed6c29bb5c1a288c838d3a1dd8bd1e8 Trojan Generic
Z6.EXE bed6c29bb5c1a288c838d3a1dd8bd1e8 Trojan Eldorado
Z6.EXE bed6c29bb5c1a288c838d3a1dd8bd1e8 Trojan CI

Z6.EXE size: 514270 bytes
Z6.EXE hash: BED6C29BB5C1A288C838D3A1DD8BD1E8

Created files:

C:\Windows\System32\DOWIRE.sys
C:\Windows\System32\z5.exe
C:\Windows\System32\z6.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\DOWIRE\Type: 01000000
HKLM\System\CurrentControlSet\Services\DOWIRE\Start: 03000000
HKLM\System\CurrentControlSet\Services\DOWIRE\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\DOWIRE\DisplayName: DOWIRE
HKLM\System\CurrentControlSet\Services\DOWIRE\ImagePath: C:\Windows\System32\DOWIRE.sys

Detected by UnHackMe:

Z6.EXE
Default location: %SYSDIR%\Z6.EXE

Dropper information:
MD5: 4e14b367a53b32515aa513c5d220b561
File size: 218112 bytes

Leave a Reply