The file CTFMOV.EXE can destroy your system, thus making the computer to work abnormally.
CTFMOV.EXE is a dangerous file.
RemoveCTFMOV.EXE from your computer immediately.
Kill the process CTFMOV.EXE and remove CTFMOV.EXE from the Windows startup.
Malware Analysis of CTFMOV.EXE
Full path on a computer: %Temp%\ctfmov.exe
Detected by UnHackMe:
CTFMOV.EXE
Default location: %Temp%\ctfmov.exe
Removal Results: Success
Number of reboot: 1
CTFMOV.EXE is known as:
Trojan.Morix, Trojan-Spy.Agent.cbot, Trojan.DownLoader6.rlsni, Trojan.Agent.Gen-Farfli, TrojWare.Spy.Agent.CBOV, Trojan.PWS.Gamania.41998, Backdoor.Morix.b (v), BDS.Morix.bh.1, Troj.Agent-WIB, TrojanSpy.Agent.wen, Troj.EncodeIe.ao.(kcloud), Backdoor.Morix.B, Backdoor.Agent.81920.W, BScope.Trojan.SvcHorse.01643, Win32.Farfli.KA, Backdoor.Morix, W32.Small.CBOT.tr
CTFMOV.EXE hash:
- MD5: d3dadbf731c28b8ca0af432913904cce
How to quickly detect CTFMOV.EXE presence?
Registry:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\819E31C7: “%WinDir%\819E31C7\svchsot.exe”
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\: “%SysDir%\kscan.exe”
- HKLM\System\CurrentControlSet\Services\Nationaljrq\ImagePath: “%SysDir%\kscan.exe”
- HKLM\System\CurrentControlSet\Services\Nationaljrq\DisplayName: “Nationalyta Instruments Domain Service”
- HKLM\System\CurrentControlSet\Services\Nationaljrq\Description: “Providesmid a domain server for NI security.”
Folders:
- %WinDir%\819E31C7
Files:
- %Temp%\ctfmov.exe
- %SysDir%\kscan.exe
- %WinDir%\Tasks\At1.job
- %WinDir%\Tasks\At10.job
- %WinDir%\Tasks\At11.job
- %WinDir%\Tasks\At12.job
- %WinDir%\Tasks\At13.job
- %WinDir%\Tasks\At14.job
- %WinDir%\Tasks\At15.job
- %WinDir%\Tasks\At16.job
- %WinDir%\Tasks\At17.job
- %WinDir%\Tasks\At18.job
- %WinDir%\Tasks\At19.job
- %WinDir%\Tasks\At2.job
- %WinDir%\Tasks\At20.job
- %WinDir%\Tasks\At21.job
- %WinDir%\Tasks\At22.job
- %WinDir%\Tasks\At23.job
- %WinDir%\Tasks\At24.job
- %WinDir%\Tasks\At3.job
- %WinDir%\Tasks\At4.job
- %WinDir%\Tasks\At5.job
- %WinDir%\Tasks\At6.job
- %WinDir%\Tasks\At7.job
- %WinDir%\Tasks\At8.job
- %WinDir%\Tasks\At9.job
- %WinDir%\819E31C7\svchsot.exe