We checked up the file ALPHA3K.EXE and found it hazardous.
The file ALPHA3K.EXE must be deleted from the system immediately.
Kill the process ALPHA3K.EXE and remove ALPHA3K.EXE from the Windows startup.
Malware Analysis of ALPHA3K.EXE
Full path on a computer: C:\antivirus\alpha3k.exe
Detected by UnHackMe:
ALPHA3K.EXE
Default location: C:\antivirus\alpha3k.exe
Removal Results: Success
Number of reboot: 1
ALPHA3K.EXE is known as:
Trojan.PWS.Siggen1.5351, a variant of Win32.Injector.ALCD, Agent4.AYYU
ALPHA3K.EXE hash:
- MD5: ea33a3e52e89a1a7590727595af1a6fe
How to quickly detect ALPHA3K.EXE presence?
Registry:
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\run: “C:\antivirus\alpha3k.exe”
Folders:
- C:\antivirus
Files:
- C:\antivirus\alpha2k.exe
- C:\antivirus\alpha3k.exe
- C:\antivirus\cygasn1-8.dll
- C:\antivirus\cygcom_err-2.dll
- C:\antivirus\cygcrypt-0.dll
- C:\antivirus\cygcrypto-1.0.0.dll
- C:\antivirus\cygcurl-4.dll
- C:\antivirus\cyggcc_s-1.dll
- C:\antivirus\cyggssapi-3.dll
- C:\antivirus\cygheimbase-1.dll
- C:\antivirus\cygheimntlm-0.dll
- C:\antivirus\cyghx509-5.dll
- C:\antivirus\cygiconv-2.dll
- C:\antivirus\cygidn-11.dll
- C:\antivirus\cygintl-8.dll
- C:\antivirus\cygkrb5-26.dll
- C:\antivirus\cyglber-2-4-2.dll
- C:\antivirus\cygldap-2-4-2.dll
- C:\antivirus\cygroken-18.dll
- C:\antivirus\cygsasl2-3.dll
- C:\antivirus\cygsqlite3-0.dll
- C:\antivirus\cygssh2-1.dll
- C:\antivirus\cygssl-1.0.0.dll
- C:\antivirus\cygwin1.dll
- C:\antivirus\cygwind-0.dll
- C:\antivirus\cygz.dll