NWJYAVSTDQG.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

NWJYAVSTDQG.EXE – Trojan Downloader removal

FileMD5Virus Alias
NWJYAVSTDQG.EXE c56d1f911d430489034e38cdfff28145 Trojan Downloader
NWJYAVSTDQG.EXE c56d1f911d430489034e38cdfff28145 Trojan SuspiciousFile
NWJYAVSTDQG.EXE c56d1f911d430489034e38cdfff28145 Trojan Generic
NWJYAVSTDQG.EXE c56d1f911d430489034e38cdfff28145 Trojan Agent

NWJYAVSTDQG.EXE size: 946407 bytes
NWJYAVSTDQG.EXE hash: C56D1F911D430489034E38CDFFF28145

Created files:

%Program Files%\DNSProtectSupport\svchost.exe
%Program Files%\DNSProtectSupport\svchost.exe.bak
%TEMP%\MFFTinGj.exe
%TEMP%\NwjyavsTDqG.exe
%TEMP%\vsTDqGc.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\DNSProtectSupport\Type: 10000000
HKLM\System\CurrentControlSet\Services\DNSProtectSupport\Start: 02000000
HKLM\System\CurrentControlSet\Services\DNSProtectSupport\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\DNSProtectSupport\ImagePath: %Program Files%\DNSProtectSupport\svchost.exe

Detected by UnHackMe:

NWJYAVSTDQG.EXE
Default location: %TEMP%\NWJYAVSTDQG.EXE

Dropper information:
MD5: 5217167f2978372e16e448ad1971e429
File size: 475472 bytes

Leave a Reply