Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

C:\M7ZTT4HC7QBV is Trojan Comet

$
0
0

The file SVCHOST.EXE.EXE can destroy your system, thus making the computer to work abnormally.
SVCHOST.EXE.EXE is a dangerous file.
RemoveSVCHOST.EXE.EXE from your computer immediately.
Kill the process SVCHOST.EXE.EXE and remove SVCHOST.EXE.EXE from the Windows startup.

Malware Analysis of C:\M7ZTT4HC7QBV
Full path on a computer: C:\M7ZTT4HC7QBV

Detected by RegRun Warrior:

Item Name: SysUpdate
Author:
Current Setting: C:\M7ztT4Hc7qBv\Windows Update/
Type: Registry Run

Item Name: UserInit
Author: Unknown
Related File: %SysDir%\userinit.exe,C:\M7ztT4Hc7qBv\Windows Update/,C:\M7ztT4Hc7qBv\Windows Update/
Type: UserInit Value

Item Name: UserInit
Author: Unknown
Related File: %SysDir%\userinit.exe,C:\M7ztT4Hc7qBv\Windows Update/,C:\M7ztT4Hc7qBv\Windows Update/
Type: UserInit Value

Removal Results: Success
Number of reboot: 1

C:\M7ZTT4HC7QBV is known as:

Trojan.Comet, Darkkomet.M, a variant of MSIL.Kryptik.PX, Backdoor.DarkKomet.bsnu, Trojan.Kazy.dQdfB4TdbAY, BackDoor.Comet.152, TR.Dropper.MSIL.18156, Backdoor.DarkKomet, MSIL.Kryptik.PX.tr, MSIL.CFXH, Backdoor.DarkKomet.aY

SVCHOST.EXE.EXE hash:

  • MD5: ac72d089724e6018f9a0c4e530e497a0
How to quickly detect SVCHOST.EXE.EXE presence?
Registry:
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SwiftKit: “%Temp%\svchost.exe.exe”
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SysUpdate: “C:\M7ztT4Hc7qBv\Windows Update/”
  • HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: “%SysDir%\userinit.exe,C:\M7ztT4Hc7qBv\Windows Update/”
Folders:
  • C:\M7ztT4Hc7qBv
Files:
  • %Temp%\svchost.exe.exe


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>