KCTEZFWGEJVY.EXE – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

KCTEZFWGEJVY.EXE – Trojan Agent removal

FileMD5Virus Alias
KCTEZFWGEJVY.EXE 4423641e4f44a3d1f0bd761d2b04d33c Trojan Agent
KCTEZFWGEJVY.EXE 4423641e4f44a3d1f0bd761d2b04d33c Trojan SuspiciousFile
KCTEZFWGEJVY.EXE 4423641e4f44a3d1f0bd761d2b04d33c Trojan Generic
KCTEZFWGEJVY.EXE 4423641e4f44a3d1f0bd761d2b04d33c Trojan Downloader
KCTEZFWGEJVY.EXE 4423641e4f44a3d1f0bd761d2b04d33c Trojan ADH

KCTEZFWGEJVY.EXE size: 474960 bytes
KCTEZFWGEJVY.EXE hash: 4423641E4F44A3D1F0BD761D2B04D33C

Created files:

%Program Files%\DNSProtectSupport\svchost.exe
%Program Files%\DNSProtectSupport\svchost.exe.bak
%TEMP%\fMZYSyU.exe
%TEMP%\kcTeZFWGEJVy.exe
%TEMP%\scFNho.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\DNSProtectSupport\Type: 10000000
HKLM\System\CurrentControlSet\Services\DNSProtectSupport\Start: 02000000
HKLM\System\CurrentControlSet\Services\DNSProtectSupport\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\DNSProtectSupport\ImagePath: %Program Files%\DNSProtectSupport\svchost.exe

Detected by UnHackMe:

KCTEZFWGEJVY.EXE
Default location: %TEMP%\KCTEZFWGEJVY.EXE

Dropper information:
MD5: 4423641e4f44a3d1f0bd761d2b04d33c
File size: 474960 bytes

Leave a Reply