Trojan OnLineGames – ksuser.dll – b1703cc602497b2d67fbdaadd88145df

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan OnLineGames
Also known as: Trojan CI, Trojan Generic
SHA256: 85add33d58ccb04d9af40fc79242b4ef2b94bdd6f082531605c1fbca3e0acbeb
SHA1: fb9257e7a27d8d9f30f85b53ae482225d6f806d2
MD5: b1703cc602497b2d67fbdaadd88145df
File size: 57856 bytes

Created files:

%SysDir%\dllcache\ksuser.dll – Trojan OnLineGames
%SysDir%\sysapp24.dll – Trojan OnLineGames
%SysDir%\yuksuser.dll – Trojan OnLineGames
%SysDir%\yumidimap.dll – Trojan OnLineGames

Trojan OnLineGames created autostart registry keys:

HKLM\System\CurrentControlSet\Control\Keyboard Layouts\E0200804\Ime File: CHINASOUGOU.IME
HKLM\System\CurrentControlSet\Control\Keyboard Layouts\E0200804\Layout Text: ????(???)???
HKLM\System\CurrentControlSet\Control\Keyboard Layouts\E0200804\Layout File: kbdus.dll
HKLM\System\CurrentControlSet\Services\cryptsvc\Start: 04000000

Leave a Reply