MicroProCon.exe – Adware Hebogo

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

MicroProCon.exe – Adware Hebogo removal

FileVirus Alias
MicroProCon.exe Adware Hebogo
MicroProCon.exe Trojan Generic

Created files:

%SysDir%\config\systemprofile\Application Data\GuardSupport\GuardConvert.exe – Adware Hebogo
%SysDir%\config\systemprofile\Application Data\MicroLab\MyEngin\Common\MicroProCon.exe – Adware Hebogo
%SysDir%\config\systemprofile\Application Data\MicroLab\MyEngin\Common\Uninstall\Uninstall.exe – Adware Hebogo

Autostart registry keys:

HKLM\Software\Classes\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59294-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59295-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MicroLabProc: %ApplicationDataFolder%\MicroLab\MyEngin\Common\MicroProCon.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MicroLabCon: %ApplicationDataFolder%\MicroLab\MyEngin\Common\MicroProCon.exe

Detected by UnHackMe:

MicroProCon.exe
Default location: %SysDir%\config\systemprofile\Application Data\MicroLab\MyEngin\Common\MicroProCon.exe

Dropper information:
SHA256: 46bb4ab733300663ec118c77ad5d6c2c886c392a9f321b724520f61608dc4af8
SHA1: ef0c380511dac87d19ee243ea20daae5660246a6
MD5: 88c9e1dc90b3eb807950856e07a5ce05
File size: 864672 bytes

Leave a Reply