Trojan OnLineGames – 20128913592.exe – 1a81e7dffe3ed63c38b6321f2d7a58b4

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan OnLineGames
Also known as: Trojan Agent, Backdoor PcClien
SHA256: 2caeeb194003f08d31522b08f8decb4145c9ea980d6da4e8743cfcccf7a7730a
SHA1: bebc0184078ed36dcfe910a2be8f12366b410d31
MD5: 1a81e7dffe3ed63c38b6321f2d7a58b4
File size: 83357 bytes

Created files:

%WinDir%\temp\20128913592.exe – Trojan OnLineGames
%WinDir%\temp\20128913594.exe – Trojan OnLineGames

Trojan OnLineGames created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\gymon: %WinDir%\temp\20128913594.exe
HKLM\System\CurrentControlSet\Services\MediaCenter\Type: 10000000
HKLM\System\CurrentControlSet\Services\MediaCenter\Start: 02000000
HKLM\System\CurrentControlSet\Services\MediaCenter\DisplayName: MS Media Control Center
HKLM\System\CurrentControlSet\Services\MediaCenter\ImagePath: %SystemRoot%\System32\svchost.exe -k start
HKLM\System\CurrentControlSet\Services\MediaCenter\Description: Provides support for media palyer. This service can’t be stoped.
HKLM\System\CurrentControlSet\Services\MediaCenter\Parameters\ServiceDll: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C00520074006D0077007400700079002E006300630033000000
HKLM\System\CurrentControlSet\Services\MediaCenter\Parameters\ServiceMain: CAONIMADESHAWO

Leave a Reply