Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

MONKDNS.EXE is Trojan Bublik.250368.C

$
0
0

The file MONKDNS.EXE is malware related.
You must delete the file MONKDNS.EXE immediately!
Delete the file MONKDNS.EXE without delay!
Kill the process MONKDNS.EXE and remove MONKDNS.EXE from the Windows startup.

Malware Analysis of MONKDNS.EXE
Full path on a computer: %SysDir%\monkdns.exe

Detected by UnHackMe:

Item Name: userinit.exe
Author: Unknown
Related File: %SYSDIR%\MONKDNS.EXE
Type: Image Executions Debugger

Removal Results: Success
Number of reboot: 1

MONKDNS.EXE is known as:

Trojan.Bublik.250368.C, Trojan.Bebloh, Trojan.Spy.Bebloh.j, Trojan.Zeroaccess.g46, Win32.Bublik.ESQBHYB, Trojan.Bublik.bavz, Trojan.Bublik.gN0JUyT1sJQ, Trojan.DownLoader9.44143, TR.Bublik.baqx, Mal.EncPk-AIT, Trojan.Bublik.B, Trojan.Bublik, Trojan.Zeroaccess, Win32.Spy.Bebloh.J, W32.Bebloh.J.tr.spy, Trj.Hexas.HEU

MONKDNS.EXE hash:

  • MD5: a9c325f11612c1b01abef3cecb114234
The file tries to download information from some web sites.
How to quickly detect MONKDNS.EXE presence?
Registry:
  • HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\userinit.exe\Debugger: “%SysDir%\monkdns.exe”
Files:
  • %SysDir%\monkdns.exe
  • %WinDir%\Temp\hlpsplay.exe


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>