| K7 Detection Name | Affected OS | Prevalence | AV Definition Version |
|---|---|---|---|
| Suspicious Program ( ID700017 ) | Windows | Low | 12.12.42356 |
| MD5 | 1d7d93fa84ba7c5a5c8b1d62acbb048d |
| SHA256 | 6d346056c766ed477967601425a4d162d15d429977910083c8a8bdd0d0c1c005 |
| File Size | 5,581,312 bytes |
| Packer Information | VMProtect |
| First Seen | 14-05-2022 |
| Last Seen | 05-09-2026 |
| Aliases | Agent.BYR |
Behavior Details
1. Creates Registry:
Adds data
1
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
Adds data
1
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
Adds data
1
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
Adds data
0
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
2. Network Activity:
Downloads
/md5.txt
from
http://www.google.com.0n6pd3we9i7mckvf.service-windows.com:83/md5.txt
Removal Instructions
1. Update K7 security to the latest version.
2. Open Windows registry editor and delete the following keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
3. Restart the machine.