MSDTE.EXE is Trojan Comisproc

June 21, 2012 by NightWatcher
Filed under: Malware 
: Solved!

Fix it immediately:

We checked up the file MSDTE.EXE and found it hazardous.
The file MSDTE.EXE must be deleted from the system immediately.
Kill the process MSDTE.EXE and remove MSDTE.EXE from the Windows startup.

Malware Analysis of MSDTE.EXE
Full path on a computer: c:\Users\usersq\msdte.exe

Detected by UnHackMe:

MSDTE.EXE
Default location: c:\Users\usersq\msdte.exe

Removal Results: Success
Number of reboot: 1

MSDTE.EXE is known as:

Trojan.Comisproc

MSDTE.EXE hash:

  • MD5: 892b4ee6b06ac37e56a3100d099a8296
How to quickly detect MSDTE.EXE presence?

Registry:
  • HKLM\SYSTEM\CurrentControlSet\Services\NetworkAccessProtectionAgent\ImagePath: “c:\Users\usersq\msdte.exe”
Folders:
  • c:\Users\usersq
Files:
  • c:\Users\usersq\msdte.exe
  • c:\Users\usersq\qsd.bat
  • c:\Users\usersq\Top Most Intelligence agencies in the world.doc
  • c:\Users\usersq\vbn.vbs
  • %System%\RunDll.bat
  • [file and pathname of the sample #1]
  • %System%\Sysinfo.txt

  • Recommended: UnHackMe anti-rootkit and anti-malware

    Premium software: RegRun Security Suite (Good choice for removal and protection)

    Written by

    Malware Hunter.

    Comments

    Tell me what you're thinking...
    and oh, if you want a pic to show with your comment, go get a gravatar!

    You must be logged in to post a comment.