<< Back to Top Threats
K7 Detection Name Affected OS Prevalence AV Definition Version
Trojan ( 005c7eb41 ) Windows Low 12.91.48569
MD5

7f915ffd0d57f177cea88f15cd74be0f

SHA256

cdc2a9b27d637718754ed25c93061a13e6a023722cb251c23a501944015d2648

File Size

10,243,072 bytes

Packer Information

N/A

First Seen

07-06-2023

Last Seen

03-06-2025

Aliases

MSIL/Agent.VQC

Behavior Details

1. Dropped files:
GDIPFONTCACHEV1.DAT
Under the folder
C:\Users\\AppData\Local

2. Dropped files:
0.txt
Under the folder
C:\Users\\AppData\Roaming\Microsoft\Windows\Cookies

3. Dropped files:
process.txt
Under the folder
C:\programdata\LSBController

4. Creates Registry:

Adds registry data
0

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet

Adds registry data
1

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect

Removal Instructions

1. Update the copy of K7 security to the latest version.
2. Scan the system completely and remove the detected files.
3. Open Windows registry editor.
4. Delete the registry data
0

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet

5. Delete the registry data
1

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
6. Close the Windows registry.
7. Restart the machine.