Trojan Swisyn – csboyDVD.dll – 9389957e83f75dae81302c3f51f37b73

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Swisyn
Also known as: Adware InstallCore, Trojan Generic
SHA256: 248d40d718561a0cb08e52cd309cb6fca3ea2f1f9dd2aa6d3313dc96e23f2870
SHA1: a4320295413804fa491fc7a21b9bf192c5f1eff9
MD5: 9389957e83f75dae81302c3f51f37b73
File size: 1448208 bytes

Created files:

%Program Files Common%\Services\csboyDVD.dll – Trojan Swisyn
%Program Files Common%\Services\csboyDvd.ocx – Trojan Swisyn
%Program Files Common%\Services\csboyTj.ocx – Trojan Swisyn
%Program Files Common%\Services\csboyTT.dll – Trojan Swisyn
%Program Files Common%\Tencent\services.exe – Trojan Swisyn
%Program Files Common%\Tencent\tuziboyAuTo.dll – Trojan Swisyn
%Program Files Common%\Tencent\tuziboyAuTo.ocx – Trojan Swisyn
%Program Files Common%\Tencent\tuziboyDw.ocx – Trojan Swisyn
%Temp%\new_ddd67.exe_6B78578B7097C08EB500D2F8B8A1C1AC01931605.exe – Trojan Swisyn

Trojan Swisyn created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ttplay: %Program Files Common%\Tencent\services.exe
HKLM\System\CurrentControlSet\Services\diskmanager\Type: 10000000
HKLM\System\CurrentControlSet\Services\diskmanager\Start: 02000000
HKLM\System\CurrentControlSet\Services\diskmanager\DisplayName: windows Disk Manager
HKLM\System\CurrentControlSet\Services\diskmanager\ImagePath: %Program Files Common%\Tencent\tuziboyAuTo.dll
HKLM\System\CurrentControlSet\Services\diskmanager\SBIE_StartTicks: E1741200

Leave a Reply