snetcfg.exe – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

snetcfg.exe – Trojan Agent removal

FileVirus Alias
snetcfg.exe Trojan Agent
snetcfg.exe Trojan Spy
snetcfg.exe Trojan Crypt
snetcfg.exe Trojan Scar
snetcfg.exe Trojan CI
snetcfg.exe Backdoor Zegost

Created files:

C:\passthru.sys – Trojan Agent
%WinDir%\inf\passthru.sys – Trojan Agent
%SysDir%\CatRoot2\edb.chk – Trojan Agent
%SysDir%\drivers\passthru.sys – Trojan Agent
%Temp%\passthru.sys – Trojan Agent
%Temp%\snetcfg.exe – Trojan Agent

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\BITS\ConnectGroup: www.cfdddos.com:3700
HKLM\System\CurrentControlSet\Services\BITS\Time: 314

Detected by UnHackMe:

snetcfg.exe
Default location: %Temp%\snetcfg.exe

Dropper information:
SHA256: 276143a66d3253aaf16be83de34981cd47350a75a5e1f6622270be22680b7d1c
SHA1: c894dcaa0237a3eb8aa60d7dd82ad72174cb0d53
MD5: ebf467f15e34d8d5571c4bf10820a151
File size: 172032 bytes

Leave a Reply