| K7 Detection Name | Affected OS | Prevalence | AV Definition Version |
|---|---|---|---|
| Riskware ( 006da5401 ) | Windows | Low | 14.37.58655 |
| MD5 | 34cf35f41494b57e27753a84055e1b6b |
| SHA256 | 961bce2ac34736470370b76f9a7d4fb3ea9d8c2b282280cf2c2b965f14017c03 |
| File Size | 13,425,936 bytes |
| Packer Information | N/A |
| First Seen | 20-02-2026 |
| Last Seen | 15-09-2026 |
| Aliases | Win32/Packed.NSIS.CU |
Behavior Details
1. Creates Registry:
Adds data
\xff\x99\xee\xfc
under
HKEY_CURRENT_USER\Fleeing222\engluttin\samlingsregeringens\Frafrtes
Adds data
Font settings
under
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\47\52C64B7E\@fontext.dll,-8007
Adds data
C:\Users\
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Unrubrical
Adds data
0
under
HKEY_CURRENT_USER\helligaftenens\Uninstall\scrimshandy\hanebjlkers
Adds data
\x01\x00\x00\x00\x00\x00\x00\x00\x11\x08\x83\x87Y\xf2\xdc\x01
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{BD84B380-8CA2-1069-AB1D-08000948F534} {000214E6-0000-0000-C000-000000000046} 0xFFFF
Removal Instructions
1. Update K7 security to the latest version.
2. Open Windows registry editor and delete the following keys:
HKEY_CURRENT_USER\Fleeing222\engluttin\samlingsregeringens\Frafrtes
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\47\52C64B7E\@fontext.dll,-8007
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Unrubrical
HKEY_CURRENT_USER\helligaftenens\Uninstall\scrimshandy\hanebjlkers
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{BD84B380-8CA2-1069-AB1D-08000948F534} {000214E6-0000-0000-C000-000000000046} 0xFFFF
3. Restart the machine.