Trojan Agent – msstart.exe – 9cf3317e4aec461fe6618df165169986

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Agent
Also known as: Trojan Jbox
SHA256: c34187daeec2ce68feac11ee8cb68b327d0195439a9eff811906c9d391170f0f
SHA1: 21f1b1a87fc22653f6c2d8a142f747d15c8a559a
MD5: 9cf3317e4aec461fe6618df165169986
File size: 33792 bytes

Created files:

%AppData%\driver.inf – Trojan Agent
%AppData%\msstart.exe – Trojan Agent
%AppData%\Plug.bat – Trojan Agent
%AppData%\ZtCtgZLC.bat – Trojan Agent

Trojan Agent created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Mshost Manager: %AppData%\msstart.exe
HKLM\System\CurrentControlSet\Services\Mshost Manager\Type: 10010000
HKLM\System\CurrentControlSet\Services\Mshost Manager\Start: 02000000
HKLM\System\CurrentControlSet\Services\Mshost Manager\DisplayName: Mshost Manager
HKLM\System\CurrentControlSet\Services\Mshost Manager\ImagePath: %AppData%\Plug.bat

Leave a Reply