Solved! Use CZOCEN.DLL (Trojan SuspiciousFile) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CZOCEN.DLL – Trojan SuspiciousFile removal

FileMD5Virus Alias
CZOCEN.DLL a1b9f97e6f46b4a7d2ed8c143588c741 Trojan SuspiciousFile

CZOCEN.DLL size: 689664 bytes
CZOCEN.DLL hash: A1B9F97E6F46B4A7D2ED8C143588C741

Created files:

%Program Files Common%\inove\fadefs.exe
%Program Files Common%\inove\foves.exe
%Program Files Common%\inove\koase\cotsen.dll
%Program Files Common%\inove\koase\czocen.dll
%Temp%\RarSFX0\Setup.EXE
%Temp%\RarSFX0\Storm3_NoAD_v1.6.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\sfcpm\Type: 10000000
HKLM\System\CurrentControlSet\Services\sfcpm\Start: 02000000
HKLM\System\CurrentControlSet\Services\sfcpm\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\sfcpm\DisplayName: System File Cache Pool Maneger
HKLM\System\CurrentControlSet\Services\sfcpm\ImagePath: %Program Files Common%\inove\foves.exe
HKLM\System\CurrentControlSet\Services\sfcpm\Description: System File Cache Pool Maneger

Detected by UnHackMe:

CZOCEN.DLL
Default location: %PROGRAM FILES COMMON%\INOVE\KOASE\CZOCEN.DLL

Dropper information:
MD5: a248e75e7fffa5f8ec0bc89d934ce8be
File size: 1885585 bytes

Leave a Reply