INTRET.CNT – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

INTRET.CNT – Trojan Agent removal

FileMD5Virus Alias
INTRET.CNT 1372cca72831ebee7acb26b8db02eef9 Trojan Agent
INTRET.CNT 1372cca72831ebee7acb26b8db02eef9 Trojan Generic
INTRET.CNT 1372cca72831ebee7acb26b8db02eef9 Trojan Xema
INTRET.CNT 1372cca72831ebee7acb26b8db02eef9 Trojan Comame
INTRET.CNT 1372cca72831ebee7acb26b8db02eef9 Trojan PAM
INTRET.CNT 1372cca72831ebee7acb26b8db02eef9 Trojan Crypt

INTRET.CNT size: 242268 bytes
INTRET.CNT hash: 1372CCA72831EBEE7ACB26B8DB02EEF9

Created files:

C:\Windows\Help\intret.cnt
C:\Windows\Syssrc32.exe
C:\Windows\System\applets.exe
C:\Windows\System\Explorer.exe
C:\Windows\System\fndfst32.exe
C:\Windows\System\mplayerw.exe
C:\Windows\System\Sysexp32.exe
C:\Windows\TEMP\1478E5.dmp

Autostart registry keys:

HKLM\Software\Classes\txtfile\shell\open\command\Explore: %SystemRoot%\System32\NOTEPAD.EXE %1
HKLM\Software\Classes\txtfile\shell\open\command : C:\Windows\System\Sysexp32.exe %1
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\System applets: C:\Windows\System\applets.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Syssrc32: C:\Windows\Syssrc32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\fndfst32: C:\Windows\System\fndfst32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Explorer Shell: C:\Windows\System\Explorer.exe

Detected by UnHackMe:

INTRET.CNT
Default location: %WinDir%\HELP\INTRET.CNT

Dropper information:
MD5: 1372cca72831ebee7acb26b8db02eef9
File size: 242268 bytes

Leave a Reply