We checked some samples of 83TENSION.EXE and detected the file 83TENSION.EXE as threat.
Remove the 83TENSION.EXE file from your computer right now.
Removal tool: http://www.unhackme.com
Malware Analysis of 83TENSION.EXE
Full path on a computer: %Temp%\83tension.exe
Detected by UnHackMe:
83TENSION.EXE
Default location: %Temp%\83tension.exe
Removal Results: Success
Number of reboot: 1
83TENSION.EXE is known as:
Trojan.Slefdel, Trojan.Agent.Gen-Autorun[Swisyn], W32.Threat-SysVenFak-based.Maxi, Win32.Spy.QQSpy.J, PE:Malware.SFBdldg.6.11A8, Trojan-GameThief.OnLineGames, W32.QQSpy.J.tr.spy, HackTool.IMEStartup.AsQJ
83TENSION.EXE hash:
- MD5: b8816499fdb51343975dc38a8d9e78e2
The file tries to download information from some web sites.
How to quickly detect 83TENSION.EXE presence?
Registry:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WinSysQQ: “%Temp%\83tension.exe”
Files:
- %Temp%\83tension.dll
- %Temp%\83tension.exe
- %Temp%\qinput.png
- %SysDir%\ImeInject.ime