Trojan OnLineGames – test.bat – 8cda28d01ee536a7f39500d8e1387d69

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan OnLineGames
Also known as: Trojan Bumat, Trojan Graftor
SHA256: c93f5aa0aeb58597bb58512ae62ee798d5fe1fae380ce938f78f34ed5be2350f
SHA1: f9a6ee2a43b012bdc86ee956d02c298f657ad8f0
MD5: 8cda28d01ee536a7f39500d8e1387d69
File size: 12800 bytes

Created files:

C:\test.bat – Trojan OnLineGames
%SysDir%\Help360tlbb.exe – Trojan OnLineGames
%SysDir%\tlbbspi.dll – Trojan OnLineGames

Trojan OnLineGames created autostart registry keys:

HKLM\System\CurrentControlSet\Services\WS2IFSL\Type: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\Start: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\DisplayName: Windows Socket 2.0 Non-IFS Service Provider Support Environment
HKLM\System\CurrentControlSet\Services\WS2IFSL\ImagePath: \SystemRoot\System32\drivers\ws2ifsl.sys

Leave a Reply