Solved! Use SYSTEMPROXY.EXE (Trojan OnLineGames) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SYSTEMPROXY.EXE – Trojan OnLineGames removal

File MD5 Virus Alias
SYSTEMPROXY.EXE 7df773ba1c695f2c5f36468367d311e8 Trojan OnLineGames
SYSTEMPROXY.EXE 7df773ba1c695f2c5f36468367d311e8 Trojan Artemis
SYSTEMPROXY.EXE 7df773ba1c695f2c5f36468367d311e8 Trojan Downloader
SYSTEMPROXY.EXE 7df773ba1c695f2c5f36468367d311e8 Backdoor Koutodoor
SYSTEMPROXY.EXE 7df773ba1c695f2c5f36468367d311e8 Trojan Agent

SYSTEMPROXY.EXE size: 154799 bytes
SYSTEMPROXY.EXE hash: 7DF773BA1C695F2C5F36468367D311E8

Created files:

%SysDir%\LspFunction.dll
%SysDir%\SystemProxy.exe
%SysDir%\UnionYxdev.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\WS2IFSL\Type: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\Start: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\DisplayName: Windows Socket 2.0 Non-IFS Service Provider Support Environment
HKLM\System\CurrentControlSet\Services\WS2IFSL\ImagePath: \SystemRoot\System32\drivers\ws2ifsl.sys

Detected by UnHackMe:

SYSTEMPROXY.EXE
Default location: %SYSDIR%\SYSTEMPROXY.EXE

Dropper information:
MD5: 7df773ba1c695f2c5f36468367d311e8
File size: 154799 bytes

Leave a Reply