CFTMON.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CFTMON.EXE – Trojan Downloader removal

FileMD5Virus Alias
CFTMON.EXE cc608e49e17ffe0c1d1290dd26330bba Trojan Downloader
CFTMON.EXE cc608e49e17ffe0c1d1290dd26330bba Trojan Adload
CFTMON.EXE cc608e49e17ffe0c1d1290dd26330bba Trojan Agent
CFTMON.EXE cc608e49e17ffe0c1d1290dd26330bba Trojan Small
CFTMON.EXE cc608e49e17ffe0c1d1290dd26330bba Trojan ZBot
CFTMON.EXE cc608e49e17ffe0c1d1290dd26330bba Trojan Crypt

CFTMON.EXE size: 447200 bytes
CFTMON.EXE hash: CC608E49E17FFE0C1D1290DD26330BBA

Created files:

%UserProfile%\cftmon.exe
%SysDir%\drivers\spools.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe
HKLM\System\CurrentControlSet\Services\Schedule\ImagePath: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0064007200690076006500720073005C00730070006F006F006C0073002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe

Detected by UnHackMe:

CFTMON.EXE
Default location: %USERPROFILE%\CFTMON.EXE

Dropper information:
MD5: 1633ecd932ef080f1c662ec86522fe0b
File size: 435786 bytes

Leave a Reply