Trojan Swisyn – lsass.exe – 5970f45238646eca80d644954efa1721

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Swisyn
Also known as: Trojan Comroki
SHA256: d9500e1c1a4f6369be2f5c81937193522dcdd3e828d1a36a689ce0bb215320e5
SHA1: b9dbd1e9a2ce2abb6605220f92a3671cc4b44792
MD5: 5970f45238646eca80d644954efa1721
File size: 212992 bytes

Created files:

%AppData%\Microsoft\lsass.exe – Trojan Swisyn

Trojan Swisyn created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\MSWUpdate: %AppData%\Microsoft\lsass.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MSWUpdate: %AppData%\Microsoft\lsass.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: C:\Windows\System32\userinit.exe,%AppData%\Microsoft\lsass.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\MSWUpdate: %AppData%\Microsoft\lsass.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MSWUpdate: %AppData%\Microsoft\lsass.exe

Leave a Reply