Spyware ( 0042b08b1 )

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

Spyware ( 0042b08b1 ) also known as DeepScan:Generic.Malware.SP!YdPk!.17FB44A7, Trojan-Downloader.Win32.Agent (A).

Malware Analysis of Spyware ( 0042b08b1 ) – ENTENG.EXE

Created files:

%Program Files Common%\msbuildnt32\enteng.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{003g66230-a069-12d1-a5ar-00eb30985445a}\: “msbuildnt32 (VML)”
HKLM\Software\Microsoft\Active Setup\Installed Components\{003g66230-a069-12d1-a5ar-00eb30985445a}\StubPath: “%Program Files Common%\msbuildnt32\enteng.exe /starta”
HKLM\Software\Microsoft\Active Setup\Installed Components\{003g66230-a069-12d1-a5ar-00eb30985445a}\ComponentID: “msbuildnt32”
HKLM\Software\Microsoft\Active Setup\Installed Components\{003g66230-a069-12d1-a5ar-00eb30985445a}\Version: “3,0,214,01”
HKLM\Software\Microsoft\Active Setup\Installed Components\{003g66230-a069-12d1-a5ar-00eb30985445a}\Locale: “EN”
HKLM\Software\Microsoft\Active Setup\Installed Components\{003g66230-a069-12d1-a5ar-00eb30985445b}\: “msbuildnt32 (VML)”
HKLM\Software\Microsoft\Active Setup\Installed Components\{003g66230-a069-12d1-a5ar-00eb30985445b}\StubPath: “%Program Files Common%\msbuildnt32\enteng.exe /startb”
HKLM\Software\Microsoft\Active Setup\Installed Components\{003g66230-a069-12d1-a5ar-00eb30985445b}\ComponentID: “msbuildnt32”
HKLM\Software\Microsoft\Active Setup\Installed Components\{003g66230-a069-12d1-a5ar-00eb30985445b}\Version: “3,0,214,01”
HKLM\Software\Microsoft\Active Setup\Installed Components\{003g66230-a069-12d1-a5ar-00eb30985445b}\Locale: “EN”

Detected by UnHackMe:

ENTENG.EXE
Default location: %PROGRAM FILES COMMON%\MSBUILDNT32\ENTENG.EXE

Dropper hash(md5): 0213afd3721928daa1fd4192c9edaf16

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

1
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera