TAMGUARD.EXE – Trojan SuspiciousFile

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

TAMGUARD.EXE – Trojan SuspiciousFile removal

FileMD5Virus Alias
TAMGUARD.EXE 0ad76618e4aa7f70931187354549dca6 Trojan SuspiciousFile
TAMGUARD.EXE 0ad76618e4aa7f70931187354549dca6 Trojan Generic

TAMGUARD.EXE size: 195096 bytes
TAMGUARD.EXE hash: 0AD76618E4AA7F70931187354549DCA6

Created files:

%AppData%\theam\common\bin\RemoveTAM.exe
%AppData%\theam\common\bin\TAMGuard.exe
%AppData%\theam\common\bin\TAMUpdate.exe
%AppData%\theam\common\bin\TheAM.exe
%SysDir%\mali.exe

Autostart registry keys:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\TheAM: %WinDir%\System32\config\Systemprofile\Application Data\theam\common\bin\TAMUpdate.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\guardtam: %WinDir%\System32\config\Systemprofile\Application Data\theam\common\bin\tamguard.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\tamgrd: %WinDir%\System32\config\Systemprofile\Application Data\theam\common\bin\TheAm.exe

Detected by UnHackMe:

TAMGUARD.EXE
Default location: %APPDATA%\THEAM\COMMON\BIN\TAMGUARD.EXE

Dropper information:
MD5: 04e09092f1d671c83ac911657c2aa8d1
File size: 839680 bytes

Leave a Reply