K7 Detection Name | Affected OS | Prevalence | AV Definition Version |
---|---|---|---|
Trojan ( 0059b4dc1 ) | Windows | Low | 12.52.45445 |
MD5 | 4ec113ac1f8e7d4dda1270cc8bb00efc |
SHA256 | 7f43ffc3c653adeff9f3b0395a78ce797d23d1faacc782955387eb276997b0ad |
File Size | 546,216 bytes |
Packer Information | N/A |
First Seen | 21-11-2022 |
Last Seen | 26-07-2023 |
Aliases | Win32/Kryptik.HRPT |
Behavior Details
1. Creates Registry: Adds registry data C:\Users\John\AppData\Local\Temp\4ec113ac1f8e7d4dda12.dat.exe Under the key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\4ec113ac1f8e7d4dda12.dat.exe
Removal Instructions
1. Update the copy of K7 security to the latest version. 2. Open Windows registry editor. 3. Delete the registry data C:\Users\John\AppData\Local\Temp\4ec113ac1f8e7d4dda12.dat.exe Under the key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\4ec113ac1f8e7d4dda12.dat.exe 4. Close the Windows registry. 5. Restart the machine.