UGF40.EXE – Suspicious File

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

UGF40.EXE – Suspicious File removal

FileMD5Virus Alias
UGF40.EXE acf380fda0e6477123f22614d1b520f1 Suspicious File
UGF40.EXE acf380fda0e6477123f22614d1b520f1 Trojan Hllw
UGF40.EXE acf380fda0e6477123f22614d1b520f1 Trojan Agent

UGF40.EXE size: 87843 bytes
UGF40.EXE hash: ACF380FDA0E6477123F22614D1B520F1

Created files:

%Program Files%\MSN Gaming Zone\Windows\bckgzm.exe
%Program Files%\MSN Gaming Zone\Windows\chkrzm.exe
%Program Files%\NetMeeting\conf.tuk
%Program Files%\Windows NT\dialer.xrm
%SysDir%\Winkdn.exe
%TEMP%\Cba3C.exe
%TEMP%\Fbs3E.exe
%TEMP%\Gqs3A.exe
%TEMP%\Ptp3D.exe
%TEMP%\Pvj3F.exe
%TEMP%\Ugf40.exe
%TEMP%\Ybj3B.exe
\\VBOXSVR\in\Qwjb.mpeg.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Winkdn\Type: 10010000
HKLM\System\CurrentControlSet\Services\Winkdn\Start: 02000000
HKLM\System\CurrentControlSet\Services\Winkdn\DisplayName: Winkdn
HKLM\System\CurrentControlSet\Services\Winkdn\ImagePath: %WinDir%\System32\Winkdn.exe
HKLM\System\CurrentControlSet\Services\ZB4dM5pkI\Type: 10010000
HKLM\System\CurrentControlSet\Services\ZB4dM5pkI\Start: 03000000
HKLM\System\CurrentControlSet\Services\ZB4dM5pkI\DisplayName: ZB4dM5pkI
HKLM\System\CurrentControlSet\Services\ZB4dM5pkI\ImagePath: \\VBOXSVR\in\Qwjb.mpeg.exe

Detected by UnHackMe:

UGF40.EXE
Default location: %TEMP%\UGF40.EXE

Dropper information:
MD5: 09be78217764b0f0a1912b3bf06cd24b
File size: 81567 bytes

Leave a Reply