Backdoor Maximus – COMDLG32.OCX – 9316619b8544e13c78b39f64262933ce

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Maximus
Also known as: Trojan Generic, Trojan Downloader.Generic
SHA256: ee4e394bba9f17cd60d25649edce1084e74440926dde1fd440e16eec51fe4a99
SHA1: 2180f79ed2ac714df77beb607692762b2a63dc47
MD5: 9316619b8544e13c78b39f64262933ce
File size: 755797 bytes

Created files:

%Temp%\COMDLG32.OCX – Backdoor Maximus
%Temp%\MSCOMCTL.OCX – Backdoor Maximus
%Temp%\tysij.ocx – Backdoor Maximus
%Temp%\ZynExplore.exe – Backdoor Maximus

Backdoor Maximus created autostart registry keys:

HKLM\Software\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}\InprocServer32 : %Temp%\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}\InprocServer32 : %Temp%\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{3C4F3BE7-47EB-101B-A3C9-08002B2F49FB}\InprocServer32 : %Temp%\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{540A5ED3-8608-4785-810F-D70E86E102C2}\InprocServer32 : %Temp%\tysij.ocx
HKLM\Software\Classes\CLSID\{540A5ED3-8608-4785-810F-D70E86E102C2}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32 : %Temp%\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32 : %Temp%\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{C27CCE32-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE33-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE34-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE35-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE36-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE37-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE38-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE39-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE3A-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE3B-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE3C-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE3D-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE3E-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE3F-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE40-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE41-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C27CCE42-8596-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\InprocServer32 : %Temp%\MSCOMCTL.OCX
HKLM\Software\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32 : %Temp%\COMDLG32.OCX
HKLM\Software\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32\ThreadingModel: Apartment

Leave a Reply