<< Back to Top Threats
K7 Detection Name Affected OS Prevalence AV Definition Version
Trojan ( 005795961 ) Windows Low 12.183.53032
MD5

234b9f45cb1693e607f7ad37deb9142e

SHA256

222d8d73829e68f869a1ead1909286fbede1583342a03e3ba5915d22262e1735

File Size

6,459,806 bytes

Packer Information

N/A

First Seen

23-08-2024

Last Seen

05-11-2024

Aliases

Win32/Packed.ExeScript.J

Behavior Details

1. Dropped files:
     irsetup.exe
     lua5.1.dll
     irsetup.dat
     IRIMG1.JPG
     IRIMG2.JPG
     IRIMG3.JPG
     irsetup.skin
     ashik Logo.ico
     ashik_Host (On).cmd
     ashik_EDIUS (11).vbs
  Under the folder
       C:\Users\<user_name>\AppData\Local\Temp\_ir_sf_temp_0

2. Creates Registry:

  Adds registry data
     0

  Under the key:
	 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet

  Adds registry data
     1

  Under the key:
	 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect

Removal Instructions

1. Update the copy of K7 security to the latest version.
2. Scan the system completely and remove the detected files.
3. Open Windows registry editor.
4. Delete the registry data
     0

   Under the key:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet

5. Delete the registry data
     1

   Under the key:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
6. Close the Windows registry.
7. Restart the machine.