Trojan Swisyn – csboyDVD.dll – 10ba72154cb73ba1ec4758095b2313a0

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Swisyn
Also known as: Trojan Agent, Trojan Downloader.Generic
SHA256: 30bc3b02a9694b1c61ee17929b2c4d6ac74ba6d175f4b0b8e7e993cd0696a040
SHA1: 8d7bfc81b6abffa6d816b54e6985a7540c6f02cc
MD5: 10ba72154cb73ba1ec4758095b2313a0
File size: 314880 bytes

Created files:

%Program Files Common%\Services\csboyDVD.dll – Trojan Swisyn
%Program Files Common%\Services\csboyDvd.ocx – Trojan Swisyn
%Program Files Common%\Services\csboyTj.ocx – Trojan Swisyn
%Program Files Common%\Services\csboyTT.dll – Trojan Swisyn
%Program Files Common%\Tencent\services.exe – Trojan Swisyn
%Program Files Common%\Tencent\tuziboyAuTo.dll – Trojan Swisyn
%Program Files Common%\Tencent\tuziboyAuTo.ocx – Trojan Swisyn
%Program Files Common%\Tencent\tuziboyDw.ocx – Trojan Swisyn
%Temp%\new_400ai.exe_0CD25E66B4D3F39A0F8EE29AEF7F96A9296E865D.exe – Trojan Swisyn

Trojan Swisyn created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ttplay: %Program Files Common%\Tencent\services.exe
HKLM\System\CurrentControlSet\Services\diskmanager\Type: 10000000
HKLM\System\CurrentControlSet\Services\diskmanager\Start: 02000000
HKLM\System\CurrentControlSet\Services\diskmanager\DisplayName: windows Disk Manager
HKLM\System\CurrentControlSet\Services\diskmanager\ImagePath: %Program Files Common%\Tencent\tuziboyAuTo.dll

Leave a Reply