Gen:Variant.Adware.Kazy.592387 (B)

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

Gen:Variant.Adware.Kazy.592387 (B) also known as Trojan.Win32.Generic!BT, AddLyrics_r.NK, Win32:Adware-gen [Adw].

Malware Analysis of Gen:Variant.Adware.Kazy.592387 (B) – 3B4992A9-7186-65FE-6A79-B24500358745.EXE

Created files:

%Local Appdata%\mixvideoplayer\log.txt
%Temp%\3B4992A9-7186-65FE-6A79-B24500358745.dll
%Temp%\3B4992A9-7186-65FE-6A79-B24500358745.exe
%Temp%\45882354-fdf5-40dd-b737-512edea8ea9c\primarycolorsetup.exe
%Temp%\71fecc75-1f12-4e6d-a7f5-92591f884ba6\mixvideoplayersetup.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\CheckMeUp\ImagePath: “%Program Files%\version65CheckMeUp\v0Zm192.exe”
HKLM\System\CurrentControlSet\Services\CheckMeUp\DisplayName: “CheckMeUp”
HKLM\System\CurrentControlSet\Services\IHProtect Service\ImagePath: “%Program Files%\XTab\ProtectService.exe”
HKLM\System\CurrentControlSet\Services\IHProtect Service\DisplayName: “IHProtect Service”
HKLM\System\CurrentControlSet\Services\MixVideoPlayerUpdaterService\ImagePath: “”%Program Files%\MixVideoPlayer\MixVideoPlayerUpdaterService.exe””
HKLM\System\CurrentControlSet\Services\MixVideoPlayerUpdaterService\DisplayName: “MixVideoPlayer Updater Service”

Detected by UnHackMe:

3B4992A9-7186-65FE-6A79-B24500358745.EXE
Default location: %TEMP%\3B4992A9-7186-65FE-6A79-B24500358745.EXE

Dropper hash(md5): 1bd0d12723069f328a1a31e37bd9cf83

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

1
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera