<< Back to Top Threats
K7 Detection Name Affected OS Prevalence AV Definition Version
Trojan-Downloader ( 005bf6071 ) Windows Low 12.212.54477
MD5

b1c0d640f28c579d65bac58ba1a84bb4

SHA256

c797733bdb414dbfe5cae129b88fa74e801a1caff00ca4090851fe8b76de4279

File Size

11,264 bytes

Packer Information

N/A

First Seen

13-01-2025

Last Seen

30-05-2025

Aliases

MSIL/TrojanDownloader.Agent.RJL

Behavior Details

1. Dropped files:
error_log.txt
Under the folder
C:\Users\\AppData\Local

2. Dropped files:
SQMHelper
Under the folder
\Device\Afd

3. Creates Registry:

Adds registry data
C:\Users\\AppData\Local\Temp\b1c0d640f28c579d65ba.dat.exe

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\MyProgram

Adds registry data
0

Under the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\b1c0d640f28c579d65ba_RASAPI32\EnableConsoleTracing

Adds registry data
18446744073709486080

Under the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\b1c0d640f28c579d65ba_RASAPI32\ConsoleTracingMask

Adds registry data
1048576

Under the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\b1c0d640f28c579d65ba_RASAPI32\MaxFileSize

Adds registry data
%windir%\tracing

Under the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\b1c0d640f28c579d65ba_RASAPI32\FileDirectory

Removal Instructions

1. Update the copy of K7 security to the latest version.
2. Scan the system completely and remove the detected files.
3. Open Windows registry editor.
4. Delete the registry data
C:\Users\\AppData\Local\Temp\b1c0d640f28c579d65ba.dat.exe

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\MyProgram

5. Delete the registry data
0

Under the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\b1c0d640f28c579d65ba_RASAPI32\EnableConsoleTracing

6. Delete the registry data
18446744073709486080

Under the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\b1c0d640f28c579d65ba_RASAPI32\ConsoleTracingMask

7. Delete the registry data
1048576

Under the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\b1c0d640f28c579d65ba_RASAPI32\MaxFileSize

8. Delete the registry data
%windir%\tracing

Under the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\b1c0d640f28c579d65ba_RASAPI32\FileDirectory
9. Close the Windows registry.
10. Restart the machine.