<< Back to Top Threats
K7 Detection Name Affected OS Prevalence AV Definition Version
Trojan ( 0055918f1 ) Windows Low 12.134.50660
MD5

cd4562e09fdb7bac0379372a0da4589c

SHA256

d8739e9f1c8c68b941ef733ea50a084411fdbf6c1738868ef7793dedc688dedc

File Size

48,640 bytes

Packer Information

N/A

First Seen

07-01-2024

Last Seen

04-03-2024

Aliases

Agent.CFQ

Behavior Details

1. Dropped files:
     $77Kanker.cmd
  Under the folder
       C:\Users\<user_name>\AppData\Roaming\eyeBeam 2.0

2. Dropped files:
     tmp1185.tmp.bat
  Under the folder
       C:\Users\<user_name>\AppData\Local\Temp

3. Creates Registry:

  Adds registry data
     0

  Under the key:
	 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet

  Adds registry data
     1

  Under the key:
	 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect

Removal Instructions

1. Update the copy of K7 security to the latest version.
2. Scan the system completely and remove the detected files.
3. Open Windows registry editor.
4. Delete the registry data
     0

   Under the key:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet

5. Delete the registry data
     1

   Under the key:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
6. Close the Windows registry.
7. Restart the machine.