Trojan OnLineGames – 201289191822.exe – 199dc55c701853b67a1d03cea81ecd63

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan OnLineGames
Also known as: Trojan Agent, Backdoor PcClien
SHA256: 7d90eb161eb82bedd1282f1b98ebfe0be3a2e1547754a95f0e9feb5ebd4e13cf
SHA1: b4154e7f6fb482b946f36b95646f38b8758fde4f
MD5: 199dc55c701853b67a1d03cea81ecd63
File size: 83357 bytes

Created files:

%WinDir%\temp\201289191822.exe – Trojan OnLineGames
%WinDir%\temp\201289191824.exe – Trojan OnLineGames

Trojan OnLineGames created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\gymon: %WinDir%\temp\201289191824.exe
HKLM\System\CurrentControlSet\Services\MediaCenter\Type: 10000000
HKLM\System\CurrentControlSet\Services\MediaCenter\Start: 02000000
HKLM\System\CurrentControlSet\Services\MediaCenter\DisplayName: MS Media Control Center
HKLM\System\CurrentControlSet\Services\MediaCenter\ImagePath: %SystemRoot%\System32\svchost.exe -k start
HKLM\System\CurrentControlSet\Services\MediaCenter\Description: Provides support for media palyer. This service can’t be stoped.
HKLM\System\CurrentControlSet\Services\MediaCenter\Parameters\ServiceDll: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0052006F006D006E007400710079002E006300630033000000
HKLM\System\CurrentControlSet\Services\MediaCenter\Parameters\ServiceMain: CAONIMADESHAWO

Leave a Reply