JMPHUJJ.DLL – Trojan OnLineGames

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

JMPHUJJ.DLL – Trojan OnLineGames removal

FileMD5Virus Alias
JMPHUJJ.DLL 3b84286d3f70a535f946364c51d35615 Trojan OnLineGames
JMPHUJJ.DLL 3b84286d3f70a535f946364c51d35615 Trojan Generic
JMPHUJJ.DLL 3b84286d3f70a535f946364c51d35615 Trojan Eldorado
JMPHUJJ.DLL 3b84286d3f70a535f946364c51d35615 Trojan Downloader
JMPHUJJ.DLL 3b84286d3f70a535f946364c51d35615 Trojan Agent
JMPHUJJ.DLL 3b84286d3f70a535f946364c51d35615 Trojan Banload

JMPHUJJ.DLL size: 5015903 bytes
JMPHUJJ.DLL hash: 3B84286D3F70A535F946364C51D35615

Created files:

%Program Files Common%\OBDC\jmphudvd.dll
%Program Files Common%\OBDC\jmphudvd.ocx
%Program Files Common%\QQDownload\jmphudw.ocx
%Program Files Common%\QQDownload\jmphujj.dll
%Program Files Common%\QQDownload\jmphujj.ocx
%Program Files Common%\QQDownload\jmphurun.dll
%Program Files Common%\QQDownload\jmphurun.ocx
%Program Files Common%\QQDownload\lsasas.exe
%TEMP%\se_dx.exe_10FECCE143398FCEBE2031D5ED26A3C03C0C7B4A.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\smsofter: %Program Files Common%\QQDownload\lsasas.exe
HKLM\System\CurrentControlSet\Services\MSmanage\Type: 10000000
HKLM\System\CurrentControlSet\Services\MSmanage\Start: 02000000
HKLM\System\CurrentControlSet\Services\MSmanage\DisplayName: windows Disk Manager
HKLM\System\CurrentControlSet\Services\MSmanage\ImagePath: %Program Files Common%\QQDownload\jmphurun.dll

Detected by UnHackMe:

JMPHUJJ.DLL
Default location: %PROGRAM FILES COMMON%\QQDOWNLOAD\JMPHUJJ.DLL

Dropper information:
MD5: 807793789b93917cadf4c5914397f175
File size: 223744 bytes

Leave a Reply