INTRET.CNT – Trojan Comame

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

INTRET.CNT – Trojan Comame removal

FileMD5Virus Alias
INTRET.CNT 0e19a441f357250d6ba5fea5fba35984 Trojan Comame
INTRET.CNT 0e19a441f357250d6ba5fea5fba35984 Trojan Generic
INTRET.CNT 0e19a441f357250d6ba5fea5fba35984 Trojan Xema
INTRET.CNT 0e19a441f357250d6ba5fea5fba35984 Trojan PAM
INTRET.CNT 0e19a441f357250d6ba5fea5fba35984 Trojan Agent
INTRET.CNT 0e19a441f357250d6ba5fea5fba35984 Trojan Crypt

INTRET.CNT size: 223846 bytes
INTRET.CNT hash: 0E19A441F357250D6BA5FEA5FBA35984

Created files:

C:\Windows\Help\intret.cnt
C:\Windows\Syssrc32.exe
C:\Windows\System\applets.exe
C:\Windows\System\Explorer.exe
C:\Windows\System\fndfst32.exe
C:\Windows\System\mplayerw.exe
C:\Windows\System\Sysexp32.exe
%Temp%\163841.dmp

Autostart registry keys:

HKLM\Software\Classes\txtfile\shell\open\command\Explore: %SystemRoot%\System32\NOTEPAD.EXE %1
HKLM\Software\Classes\txtfile\shell\open\command : C:\Windows\System\Sysexp32.exe %1
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\System applets: C:\Windows\System\applets.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Syssrc32: C:\Windows\Syssrc32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\fndfst32: C:\Windows\System\fndfst32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Explorer Shell: C:\Windows\System\Explorer.exe

Detected by UnHackMe:

INTRET.CNT
Default location: %WinDir%\HELP\INTRET.CNT

Dropper information:
MD5: 0e19a441f357250d6ba5fea5fba35984
File size: 223846 bytes

Leave a Reply