EASYPOP_E.EXE – Trojan Crypt

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

EASYPOP_E.EXE – Trojan Crypt removal

FileMD5Virus Alias
EASYPOP_E.EXE 6810e6551cb2817a531ca5546211d422 Trojan Crypt
EASYPOP_E.EXE 6810e6551cb2817a531ca5546211d422 Trojan Downloader
EASYPOP_E.EXE 6810e6551cb2817a531ca5546211d422 Backdoor Maximus

EASYPOP_E.EXE size: 298560 bytes
EASYPOP_E.EXE hash: 6810E6551CB2817A531CA5546211D422

Created files:

%AppData%\EasyPop\EasyPop_E.exe
%AppData%\EasyPop\EasyPop_R.exe
%AppData%\EasyPop\EasyPop_S.exe
%AppData%\EasyPop\EasyPop_U.exe
%AppData%\EasyPop\NTVBSvc.tlb
%AppData%\EasyPop\uninst_check.exe
%AppData%\EasyPop\zlib.dll

Autostart registry keys:

HKLM\Software\Classes\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59294-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59295-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX

Detected by UnHackMe:

EASYPOP_E.EXE
Default location: %APPDATA%\EASYPOP\EASYPOP_E.EXE

Dropper information:
MD5: 5caa6a3c135d31a5b850ac509c50b474
File size: 787120 bytes

Leave a Reply