Solved! Use SPOO3213SV.EXE (Trojan OnLineGames) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SPOO3213SV.EXE – Trojan OnLineGames removal

File MD5 Virus Alias
SPOO3213SV.EXE 2973be93fd37b5489a833b7182a85384 Trojan OnLineGames
SPOO3213SV.EXE 2973be93fd37b5489a833b7182a85384 Trojan PAK_Generic
SPOO3213SV.EXE 2973be93fd37b5489a833b7182a85384 Trojan Artemis
SPOO3213SV.EXE 2973be93fd37b5489a833b7182a85384 Trojan Xema
SPOO3213SV.EXE 2973be93fd37b5489a833b7182a85384 Trojan Agent

SPOO3213SV.EXE size: 92160 bytes
SPOO3213SV.EXE hash: 2973BE93FD37B5489A833B7182A85384

Created files:

%SysDir%\3.dll
%SysDir%\spoo3213sv.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\SoulService\Type: 10010000
HKLM\System\CurrentControlSet\Services\SoulService\Start: 02000000
HKLM\System\CurrentControlSet\Services\SoulService\DisplayName: Remote Control Service
HKLM\System\CurrentControlSet\Services\SoulService\ImagePath: %WinDir%\System32\spoo3213sv.exe

Detected by UnHackMe:

SPOO3213SV.EXE
Default location: %SYSDIR%\SPOO3213SV.EXE

Dropper information:
MD5: 2973be93fd37b5489a833b7182a85384
File size: 92160 bytes

Leave a Reply