Solved! Use RBDRHKIOJ.PIC (Trojan Magania) Removal Guide

I will tell you in this post how to fix the issue manually and how to clean it automatically using a special powerful removal tool. You can download the removal program for free here:

Manual removal instructions:

RBDRHKIOJ.PIC – Trojan Magania removal

File MD5 Virus Alias
RBDRHKIOJ.PIC 32cfc0645b7818e24711a21e8ae6609b Trojan Magania
RBDRHKIOJ.PIC 32cfc0645b7818e24711a21e8ae6609b Trojan Eldorado
RBDRHKIOJ.PIC 32cfc0645b7818e24711a21e8ae6609b Trojan Downloader
RBDRHKIOJ.PIC 32cfc0645b7818e24711a21e8ae6609b Trojan Barys
RBDRHKIOJ.PIC 32cfc0645b7818e24711a21e8ae6609b Trojan OnLineGames
RBDRHKIOJ.PIC 32cfc0645b7818e24711a21e8ae6609b Backdoor Zegost

RBDRHKIOJ.PIC size: 3920384 bytes
RBDRHKIOJ.PIC hash: 32CFC0645B7818E24711A21E8AE6609B

Created files:

%Program Files%\Kxbq\Rbdrhkioj.pic

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Kuavhy Tvxmkyhl Quw\Type: 10010000
HKLM\System\CurrentControlSet\Services\Kuavhy Tvxmkyhl Quw\Start: 02000000
HKLM\System\CurrentControlSet\Services\Kuavhy Tvxmkyhl Quw\DisplayName: Avmwil Xrdbbrlx Igdrpwsk Yqxm
HKLM\System\CurrentControlSet\Services\Kuavhy Tvxmkyhl Quw\ImagePath: %SystemRoot%\System32\svchost.exe -k imgsvc
HKLM\System\CurrentControlSet\Services\Kuavhy Tvxmkyhl Quw\ConnectGroup: Default

Detected by UnHackMe:

RBDRHKIOJ.PIC
Default location: %PROGRAM FILES%\KXBQ\RBDRHKIOJ.PIC

Dropper information:
MD5: c6c9616b7b13f98cf5618185be2b01c3
File size: 308736 bytes

Leave a Reply