Trojan Swisyn – qasf.dll – 4a965d685036ac5782af343a9afcc364

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Swisyn
Also known as: Trojan Zbot, Worm Autorun
SHA256: 28c6a2754df2d4cc0746ebb59a230f6aa2cdb20ca12365211b5c8d5ec73ac923
SHA1: 5f5132b86bc47c5bffeac9c9b98eef36ab3028c7
MD5: 4a965d685036ac5782af343a9afcc364
File size: 67072 bytes

Created files:

%WinDir%\Config\qasf.dll – Trojan Swisyn
%WinDir%\Cursors\ieui.dll – Trojan Swisyn
%WinDir%\ie8\upnp.dll – Trojan Swisyn
%WinDir%\inf\ver.dll – Trojan Swisyn
%AppData%\test.inf – Trojan Swisyn

Trojan Swisyn created autostart registry keys:

HKLM\Software\Classes\CLSID\{0F4126CD-58D5-450C-ABF7-C2AE5A0866B0}\InprocServer32 : %WinDir%\ie8\upnp.dll
HKLM\Software\Classes\CLSID\{0F4126CD-58D5-450C-ABF7-C2AE5A0866B0}\InprocServer32\ThreadingModel: Apartment

Leave a Reply