Trojan OnLineGames – ksuser.dll – c7e776ee2de813696788c480b92dbeea

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

Trojan OnLineGames
Also known as: Backdoor PcClien, Trojan Generic
SHA256: a5c58400639b38487557730744d6a21a8b4d8039adc3929779b57c9f2841479b
SHA1: 11f95b95f08e73fc241e3f001bbc2672bd2fabb8
MD5: c7e776ee2de813696788c480b92dbeea
File size: 49664 bytes

Created files:

%SysDir%\dllcache\ksuser.dll – Trojan OnLineGames
%SysDir%\sysapp23.dll – Trojan OnLineGames
%SysDir%\yuksuser.dll – Trojan OnLineGames
%SysDir%\yumidimap.dll – Trojan OnLineGames

Trojan OnLineGames created autostart registry keys:

HKLM\System\CurrentControlSet\Control\Keyboard Layouts\E0200804\Ime File: CHINASOUGOU.IME
HKLM\System\CurrentControlSet\Control\Keyboard Layouts\E0200804\Layout Text: ????(???)???
HKLM\System\CurrentControlSet\Control\Keyboard Layouts\E0200804\Layout File: kbdus.dll
HKLM\System\CurrentControlSet\Services\cryptsvc\Start: 04000000

Leave a Reply