Solved! Use FOVES.EXE (Trojan SuspiciousFile) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

FOVES.EXE – Trojan SuspiciousFile removal

FileMD5Virus Alias
FOVES.EXE cd3363642775fa1904291b4bf10cd8e6 Trojan SuspiciousFile

FOVES.EXE size: 892928 bytes
FOVES.EXE hash: CD3363642775FA1904291B4BF10CD8E6

Created files:

%Program Files Common%\inove\fadefs.exe
%Program Files Common%\inove\foves.exe
%Program Files Common%\inove\koase\cotsen.dll
%Program Files Common%\inove\koase\czocen.dll
%Temp%\RarSFX0\Setup.EXE
%Temp%\RarSFX0\Storm3_NoAD_v1.6.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\sfcpm\Type: 10000000
HKLM\System\CurrentControlSet\Services\sfcpm\Start: 02000000
HKLM\System\CurrentControlSet\Services\sfcpm\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\sfcpm\DisplayName: System File Cache Pool Maneger
HKLM\System\CurrentControlSet\Services\sfcpm\ImagePath: %Program Files Common%\inove\foves.exe
HKLM\System\CurrentControlSet\Services\sfcpm\Description: System File Cache Pool Maneger

Detected by UnHackMe:

FOVES.EXE
Default location: %PROGRAM FILES COMMON%\INOVE\FOVES.EXE

Dropper information:
MD5: a248e75e7fffa5f8ec0bc89d934ce8be
File size: 1885585 bytes

Leave a Reply