MSGTF32.EXE – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

MSGTF32.EXE – Trojan Agent removal

FileMD5Virus Alias
MSGTF32.EXE d502425a0e1a94811d1595605589212e Trojan Agent
MSGTF32.EXE d502425a0e1a94811d1595605589212e Suspicious File
MSGTF32.EXE d502425a0e1a94811d1595605589212e Trojan Small

MSGTF32.EXE size: 769289 bytes
MSGTF32.EXE hash: D502425A0E1A94811D1595605589212E

Created files:

%WinDir%\svchost.exe
%SysDir%\concp32.exe
%SysDir%\explorer.exe
%SysDir%\msgtf32.exe
%SysDir%\vcl32.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{E4883584-8B9A-11D5-EBA1-F78EEEEEE983}\StubPath: msgtf32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VCL: vcl32.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VCL: vcl32.exe

Detected by UnHackMe:

MSGTF32.EXE
Default location: %SYSDIR%\MSGTF32.EXE

Dropper information:
MD5: 08748294df6a657e6a06a4ac3e8e6606
File size: 743539 bytes

Leave a Reply