The file MONKDNS.EXE is malware related.
You must delete the file MONKDNS.EXE immediately!
Delete the file MONKDNS.EXE without delay!
Kill the process MONKDNS.EXE and remove MONKDNS.EXE from the Windows startup.
Malware Analysis of MONKDNS.EXE
Full path on a computer: %SysDir%\monkdns.exe
Detected by UnHackMe:
Item Name: userinit.exe
Author: Unknown
Related File: %SYSDIR%\MONKDNS.EXE
Type: Image Executions Debugger
Removal Results: Success
Number of reboot: 1
MONKDNS.EXE is known as:
Trojan.Bublik.250368.C, Trojan.Bebloh, Trojan.Spy.Bebloh.j, Trojan.Zeroaccess.g46, Win32.Bublik.ESQBHYB, Trojan.Bublik.bavz, Trojan.Bublik.gN0JUyT1sJQ, Trojan.DownLoader9.44143, TR.Bublik.baqx, Mal.EncPk-AIT, Trojan.Bublik.B, Trojan.Bublik, Trojan.Zeroaccess, Win32.Spy.Bebloh.J, W32.Bebloh.J.tr.spy, Trj.Hexas.HEU
MONKDNS.EXE hash:
- MD5: a9c325f11612c1b01abef3cecb114234
The file tries to download information from some web sites.
How to quickly detect MONKDNS.EXE presence?
Registry:
- HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\userinit.exe\Debugger: “%SysDir%\monkdns.exe”
Files:
- %SysDir%\monkdns.exe
- %WinDir%\Temp\hlpsplay.exe