Trojan Agent – AdvTCApp.exe – e450834d1988b8b56f7d6d257630516c

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Agent
Also known as: Backdoor Ping, Trojan CI
SHA256: 16b1c85fa37a371418a2c8cfb36f52c2f56160ed5c63513631f237bd1d05895a
SHA1: 015c6f30faa160efeffed2d82e833e24525b9e10
MD5: e450834d1988b8b56f7d6d257630516c
File size: 581704 bytes

Created files:

%Program Files%\AdvTopC\AdvTCApp.exe – Trojan Agent
%Program Files%\AdvTopC\TCCheckAgent.exe – Trojan Agent
%Program Files%\AdvTopC\TCHelper.dll – Trojan Agent
%Program Files%\AdvTopC\TCUnins.exe – Trojan Agent

Trojan Agent created autostart registry keys:

HKLM\Software\Classes\CLSID\{3E5EF872-03E2-4CE0-94DF-CA8A5004ECFD}\InprocServer32 : %Program Files%\AdvTopC\TCHelper.dll
HKLM\Software\Classes\CLSID\{3E5EF872-03E2-4CE0-94DF-CA8A5004ECFD}\InprocServer32\ThreadingModel: Apartment
HKLM\System\CurrentControlSet\Services\TCCheckAgent\Type: 10010000
HKLM\System\CurrentControlSet\Services\TCCheckAgent\Start: 02000000
HKLM\System\CurrentControlSet\Services\TCCheckAgent\DisplayName: TCCheckAgent
HKLM\System\CurrentControlSet\Services\TCCheckAgent\ImagePath: %Program Files%\AdvTopC\TCCheckAgent.exe

Leave a Reply