<< Back to Top Threats
K7 Detection Name Affected OS Prevalence AV Definition Version
Trojan ( 005823691 ) Windows Low 12.136.50776
MD5

e6a7ab4cbf74837d2e4687a1fba0fee3

SHA256

50f22006624f92bf4c358e9ef8c32f9ef8a2cd2723eaa2085f879048ba43d2a2

File Size

32,255,792 bytes

Packer Information

N/A

First Seen

18-01-2024

Last Seen

13-11-2024

Aliases

Win64/Packed.Enigma.BV

Behavior Details

1. Dropped files:
     e6a7ab4cbf74837d2e46.dat.tmp
  Under the folder
       C:\Users\<user_name>\AppData\Local\Temp\is-IU2IE.tmp

2. Dropped files:
     _RegDLL.tmp
     _setup64.tmp
     _shfoldr.dll
  Under the folder
       C:\Users\<user_name>\AppData\Local\Temp\is-V1JDG.tmp\_isetup

3. Creates Registry:

  Adds registry data
     \xb0\x08\x00\x00\x94z\x91\xeb\xc41\xdb\x01

  Under the key:
	 HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Owner

  Adds registry data
     O\x13\x88Y\xbd\xd4\xb5w:U
n\x7f\x9e3\xc6\x892\xf6\x8d\xd95\xba\x9a\x92D{\x80/\xdaS\x1c

  Under the key:
	 HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\SessionHash

  Adds registry data
     1

  Under the key:
	 HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Sequence

Removal Instructions

1. Update the copy of K7 security to the latest version.
2. Scan the system completely and remove the detected files.
3. Open Windows registry editor.
4. Delete the registry data
     \xb0\x08\x00\x00\x94z\x91\xeb\xc41\xdb\x01

   Under the key:
    HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Owner

5. Delete the registry data
     O\x13\x88Y\xbd\xd4\xb5w:U
n\x7f\x9e3\xc6\x892\xf6\x8d\xd95\xba\x9a\x92D{\x80/\xdaS\x1c

   Under the key:
    HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\SessionHash

6. Delete the registry data
     1

   Under the key:
    HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Sequence
7. Close the Windows registry.
8. Restart the machine.