Trojan Magania – ordkool.dll – 7b20c2bf54dfc368c60a20b57a964db3

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Magania
Also known as: Trojan Agent, Backdoor Zegost
SHA256: 55295a880a40c43faec681e475964db65a88eb867c47fa9ad92ad2edc452e27e
SHA1: 563354002a02ee88c636cedab8cad0bfb9cf3fdc
MD5: 7b20c2bf54dfc368c60a20b57a964db3
File size: 81510 bytes

Created files:

%SysDir%\ordkool.dll – Trojan Magania

Trojan Magania created autostart registry keys:

HKLM\System\CurrentControlSet\Services\6to4\Type: 04000000
HKLM\System\CurrentControlSet\Services\6to4\Start: 02000000
HKLM\System\CurrentControlSet\Services\6to4\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\6to4\DisplayName: ChuanShanJia
HKLM\System\CurrentControlSet\Services\6to4\ImagePath: %SystemRoot%\System32\svchost.exe -k netsvcs
HKLM\System\CurrentControlSet\Services\6to4\Description: 5.2?????
HKLM\System\CurrentControlSet\Services\6to4\TXllASleWBH: 7B20C2BF54DFC368C60A20B57A964DB3_7B20C2BF54DFC368C60A20B57A964DB3.EXE
HKLM\System\CurrentControlSet\Services\6to4\Parameters\ServiceDll: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C006F00720064006B006F006F006C002E0064006C006C000000
HKLM\System\CurrentControlSet\Services\6to4\Parameters\ServiceMain: PangolinMain

Leave a Reply