SYSTEM.EXE – Trojan OnLineGames

I will tell you in this post how to fix the issue manually and how to clean it automatically using a special powerful removal tool. You can download the removal program for free here:

Manual removal instructions:

SYSTEM.EXE – Trojan OnLineGames removal

File MD5 Virus Alias
SYSTEM.EXE 7b309f704781fd100c58f9a03d534351 Trojan OnLineGames
SYSTEM.EXE 7b309f704781fd100c58f9a03d534351 Trojan Lineage
SYSTEM.EXE 7b309f704781fd100c58f9a03d534351 Trojan Generic
SYSTEM.EXE 7b309f704781fd100c58f9a03d534351 Trojan Siggen
SYSTEM.EXE 7b309f704781fd100c58f9a03d534351 Trojan Agent

SYSTEM.EXE size: 7680 bytes
SYSTEM.EXE hash: 7B309F704781FD100C58F9A03D534351

Created files:

%SysDir%\drivers\HBKernel32.sys
%SysDir%\HBYY.dll
%SysDir%\System.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\HBService32: System.exe
HKLM\System\CurrentControlSet\Services\HBKernel32\Type: 01000000
HKLM\System\CurrentControlSet\Services\HBKernel32\DisplayName: HBKernel32 Driver
HKLM\System\CurrentControlSet\Services\HBKernel32\ImagePath: %WinDir%\System32\drivers\HBKernel32.sys

Detected by UnHackMe:

SYSTEM.EXE
Default location: %SYSDIR%\SYSTEM.EXE

Dropper information:
MD5: 2b9b5bbb19717ed8a1b8e9b3bf1d71cd
File size: 17153 bytes

Leave a Reply