| K7 Detection Name | Affected OS | Prevalence | AV Definition Version |
|---|---|---|---|
| Trojan ( 006d9d061 ) | Windows | Low | 14.32.58455 |
| MD5 | 9bfa7a2991a8b62b5ef12a920b220e1e |
| SHA256 | ec860277d21159deb084b7849149a3700d98dc42d7d69e2e3acceed6dbe3158e |
| File Size | 6,904,320 bytes |
| Packer Information | N/A |
| First Seen | 31-01-2026 |
| Last Seen | 08-07-2026 |
| Aliases | Agent.GPN |
Behavior Details
1. Creates Registry:
Adds data
C:\Windows\System32\u776287.dll
under
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\u776287\Parameters\ServiceDll
Adds data
\x00\x00\x00\x00\x00\x00\x00\x00
under
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\DcomLaunch
Removal Instructions
1. Update K7 security to the latest version.
2. Open Windows registry editor and delete the following keys:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\u776287\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\DcomLaunch
3. Restart the machine.