Trojan Swisyn – csboyDVD.dll – 778b410c7377d8f7dbb905f7baf7825c

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Swisyn
Also known as: Trojan Downloader.Generic, Trojan Generic
SHA256: be801839a8a4023ab10704225be0246425601390a815593fbb0f6c235335459d
SHA1: b4eee414d78d9e12d86fcfad72a421dc398609f7
MD5: 778b410c7377d8f7dbb905f7baf7825c
File size: 309760 bytes

Created files:

%Program Files Common%\Services\csboyDVD.dll – Trojan Swisyn
%Program Files Common%\Services\csboyDvd.ocx – Trojan Swisyn
%Program Files Common%\Services\csboyTj.ocx – Trojan Swisyn
%Program Files Common%\Services\csboyTT.dll – Trojan Swisyn
%Program Files Common%\Tencent\services.exe – Trojan Swisyn
%Program Files Common%\Tencent\tuziboyAuTo.dll – Trojan Swisyn
%Program Files Common%\Tencent\tuziboyAuTo.ocx – Trojan Swisyn
%Program Files Common%\Tencent\tuziboyDw.ocx – Trojan Swisyn
%Temp%\qvod.exe_9903B248AEE904AA3F0A852E910629F6D8046A51.exe – Trojan Swisyn

Trojan Swisyn created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ttplay: %Program Files Common%\Tencent\services.exe
HKLM\System\CurrentControlSet\Services\diskmanager\Type: 10000000
HKLM\System\CurrentControlSet\Services\diskmanager\Start: 02000000
HKLM\System\CurrentControlSet\Services\diskmanager\DisplayName: windows Disk Manager
HKLM\System\CurrentControlSet\Services\diskmanager\ImagePath: %Program Files Common%\Tencent\tuziboyAuTo.dll
HKLM\System\CurrentControlSet\Services\diskmanager\SBIE_StartTicks: 545D4500

Leave a Reply