SUPEREC.PROCESSMEMORY.SYS – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SUPEREC.PROCESSMEMORY.SYS – Trojan Agent removal

FileMD5Virus Alias
SUPEREC.PROCESSMEMORY.SYS 7fc8f430b830c119640c606de9bb907c Trojan Agent
SUPEREC.PROCESSMEMORY.SYS 7fc8f430b830c119640c606de9bb907c Suspicious File
SUPEREC.PROCESSMEMORY.SYS 7fc8f430b830c119640c606de9bb907c Trojan Generic
SUPEREC.PROCESSMEMORY.SYS 7fc8f430b830c119640c606de9bb907c Trojan Eldorado
SUPEREC.PROCESSMEMORY.SYS 7fc8f430b830c119640c606de9bb907c Trojan Small

SUPEREC.PROCESSMEMORY.SYS size: 3712 bytes
SUPEREC.PROCESSMEMORY.SYS hash: 7FC8F430B830C119640C606DE9BB907C

Created files:

%TEMP%\UnicodeFile.bin
%TEMP%\fengye66.exe
%TEMP%\Hook.dll
%TEMP%\SkinH_EL.dll
%TEMP%\superec.ProcessMemory.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\ialdnwxf\Type: 01000000
HKLM\System\CurrentControlSet\Services\ialdnwxf\Start: 03000000
HKLM\System\CurrentControlSet\Services\ialdnwxf\DisplayName: ialdnwxf
HKLM\System\CurrentControlSet\Services\ialdnwxf\ImagePath: %TEMP%\\superec.ProcessMemory.sys

Detected by UnHackMe:

SUPEREC.PROCESSMEMORY.SYS
Default location: %TEMP%\SUPEREC.PROCESSMEMORY.SYS

Dropper information:
MD5: 09aad2de6c331263ea7bf0e5939944b9
File size: 1380352 bytes

Leave a Reply