CENTERV.GZIP – Trojan Magania

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

CENTERV.GZIP – Trojan Magania removal

File MD5 Virus Alias
CENTERV.GZIP 5c8fb45587d7b78b0352871ed20b4a6f Trojan Magania
CENTERV.GZIP 5c8fb45587d7b78b0352871ed20b4a6f Trojan SuspiciousFile
CENTERV.GZIP 5c8fb45587d7b78b0352871ed20b4a6f Trojan Eldorado
CENTERV.GZIP 5c8fb45587d7b78b0352871ed20b4a6f Trojan Downloader
CENTERV.GZIP 5c8fb45587d7b78b0352871ed20b4a6f Trojan Graftor
CENTERV.GZIP 5c8fb45587d7b78b0352871ed20b4a6f Trojan OnLineGames

CENTERV.GZIP size: 1475584 bytes
CENTERV.GZIP hash: 5C8FB45587D7B78B0352871ED20B4A6F

Created files:

C:\Net-mysql.sql
%Program Files Common%\Centerv.gzip
C:\windows\Prefetch1423300.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\MeudiayCenterl\Type: 10010000
HKLM\System\CurrentControlSet\Services\MeudiayCenterl\Start: 02000000
HKLM\System\CurrentControlSet\Services\MeudiayCenterl\DisplayName: MS Mediax Controlv Centerv
HKLM\System\CurrentControlSet\Services\MeudiayCenterl\ImagePath: %SystemRoot%\System32\svchost.exe -k imgsvc
HKLM\System\CurrentControlSet\Services\RemoteAccess\RouterManagers\Ip\DLLPath: 43003A005C00770069006E0064006F00770073005C005000720065006600650074006300680031003400320033003300300030002E0064006C006C000000

Detected by UnHackMe:

CENTERV.GZIP
Default location: %PROGRAM FILES COMMON%\CENTERV.GZIP

Dropper information:
MD5: 447eac0746441420462a11a3539a6df0
File size: 176128 bytes

Leave a Reply