Solved! Use BOOTER.EXE (Trojan Agent) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

BOOTER.EXE – Trojan Agent removal

File MD5 Virus Alias
BOOTER.EXE ccbe1775eb280c1b6187628534fc34da Trojan Agent
BOOTER.EXE ccbe1775eb280c1b6187628534fc34da Trojan DLOADER
BOOTER.EXE ccbe1775eb280c1b6187628534fc34da Trojan SuspiciousFile
BOOTER.EXE ccbe1775eb280c1b6187628534fc34da Trojan Generic
BOOTER.EXE ccbe1775eb280c1b6187628534fc34da Trojan Downloader
BOOTER.EXE ccbe1775eb280c1b6187628534fc34da Worm Autorun

BOOTER.EXE size: 248832 bytes
BOOTER.EXE hash: CCBE1775EB280C1B6187628534FC34DA

Created files:

C:\booter.exe
C:\DelInfo.bin
%TEMP%\Forter.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\bits\Start: 02000000
HKLM\System\CurrentControlSet\Services\Forter\Type: 01000000
HKLM\System\CurrentControlSet\Services\Forter\Start: 03000000
HKLM\System\CurrentControlSet\Services\Forter\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Forter\DisplayName: Forter
HKLM\System\CurrentControlSet\Services\Forter\ImagePath: %TEMP%\Forter.sys

Detected by UnHackMe:

BOOTER.EXE
Default location: C:\BOOTER.EXE

Dropper information:
MD5: a9695eecab156f4cbf10830a3cd0d289
File size: 310784 bytes

Leave a Reply