Trojan Magania – osyuok.exe – 2d6ff4459ed2689363cb7ab583acdf7c

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Magania
Also known as: Trojan Siggen
SHA256: 1a56a6d56f06a1c78b10ecb19935aeeb27c9c6309d2f96b35362a3dff8afc77d
SHA1: dab8805029d22090eaee6ce21ef302107a70fee4
MD5: 2d6ff4459ed2689363cb7ab583acdf7c
File size: 143360 bytes

Created files:

%SysDir%\osyuok.exe – Trojan Magania
%WinDir%\TEMP\Server.dll – Trojan Magania

Trojan Magania created autostart registry keys:

HKLM\System\CurrentControlSet\Services\BITS\ConnectGroup: camfrog4.3322.org:9033
HKLM\System\CurrentControlSet\Services\BITS\Time: 250
HKLM\System\CurrentControlSet\Services\Logical jrq Disk Manager\Type: 10000000
HKLM\System\CurrentControlSet\Services\Logical jrq Disk Manager\Start: 02000000
HKLM\System\CurrentControlSet\Services\Logical jrq Disk Manager\DisplayName: Logical yta Disk Manager Service
HKLM\System\CurrentControlSet\Services\Logical jrq Disk Manager\ImagePath: %WinDir%\System32\osyuok.exe
HKLM\System\CurrentControlSet\Services\Logical jrq Disk Manager\Description: Logical mid Disk Manager Service for NI security.

Leave a Reply