<< Back to Top Threats
K7 Detection Name Affected OS Prevalence AV Definition Version
Suspicious Program ( ID700017 ) Windows Low 12.12.42356
MD5

1d7d93fa84ba7c5a5c8b1d62acbb048d

SHA256

6d346056c766ed477967601425a4d162d15d429977910083c8a8bdd0d0c1c005

File Size

5,581,312 bytes

Packer Information

VMProtect

First Seen

14-05-2022

Last Seen

05-09-2026

Aliases

Agent.BYR

Behavior Details

1. Creates Registry:
Adds data
1
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
Adds data
1
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
Adds data
1
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
Adds data
0
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect

2. Network Activity:
Downloads
/md5.txt
from
http://www.google.com.0n6pd3we9i7mckvf.service-windows.com:83/md5.txt

Removal Instructions

1. Update K7 security to the latest version.
2. Open Windows registry editor and delete the following keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
3. Restart the machine.