BC2001.exe – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

BC2001.exe – Trojan Agent removal

FileVirus Alias
BC2001.exe Trojan Agent
BC2001.exe Trojan Siggen
BC2001.exe Trojan PWS
BC2001.exe Trojan Generic

Created files:

%Program Files%\BonusCash\BCSTS.dll – Trojan Agent
%Program Files%\BonusCash\BonusCash.dll – Trojan Agent
%Program Files%\BonusCash\BonusCash.exe – Trojan Agent
%Program Files%\BonusCash\BonusCashDll.dll – Trojan Agent
%Program Files%\BonusCash\uninstall.exe – Trojan Agent
%Temp%\BC2001.exe – Trojan Agent

Autostart registry keys:

HKLM\Software\Classes\CLSID\{012C7D93-B5A0-4be3-A2F8-A02BF1EE5751}\InprocServer32 : %Program Files%\BonusCash\BonusCash.dll
HKLM\Software\Classes\CLSID\{F2CF5485-4E02-4F68-819C-B92DE9277049}\InprocServer32 : %WinDir%\System32\ieframe.dll
HKLM\Software\Classes\CLSID\{F2CF5485-4E02-4F68-819C-B92DE9277049}\InprocServer32\MenuTextPUI: @ieframe.dll,-13138
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\BonusCash: %Program Files%\BonusCash\BonusCash.exe

Detected by UnHackMe:

BC2001.exe
Default location: %Temp%\BC2001.exe

Dropper information:
SHA256: 9dcac39dd4498060684f738e73f3debdc83c9c6be1573edeae2a8a3f33776cd0
SHA1: a088e01112927a88a218bf65501b566dcc5dea75
MD5: 989a07b4df8b1923a929fc92f933dd8f
File size: 82944 bytes

Leave a Reply