win2k2.dll – Trojan Generic

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

win2k2.dll – Trojan Generic removal

FileVirus Alias
win2k2.dll Trojan Generic
win2k2.dll Trojan Bumat
win2k2.dll Trojan CI
win2k2.dll Backdoor PcClien
win2k2.dll Trojan Agent

Created files:

%SysDir%\AudioDevUI.exe – Trojan Generic
%SysDir%\inetlink.exe – Trojan Generic
%SysDir%\sqlview.exe – Trojan Generic
%SysDir%\ssdll.dll – Trojan Generic
%SysDir%\temp2.bin – Trojan Generic
%SysDir%\temp222.bin – Trojan Generic
%SysDir%\win2k1.dll – Trojan Generic
%SysDir%\win2k2.dll – Trojan Generic

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\NdisServer\Type: 10000000
HKLM\System\CurrentControlSet\Services\NdisServer\Start: 02000000
HKLM\System\CurrentControlSet\Services\NdisServer\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\NdisServer\DisplayName: Network Distribution Service
HKLM\System\CurrentControlSet\Services\NdisServer\ImagePath: %SystemRoot%\System32\inetlink.exe
HKLM\System\CurrentControlSet\Services\NdisServer\Description: Network Service Remote Access Manager Service.

Detected by UnHackMe:

win2k2.dll
Default location: %SysDir%\win2k2.dll

Dropper information:
SHA256: 870db6bf55bfa454497d0edd1418c19f186ee3d723ab2263f7993e4d78826a00
SHA1: 9a5b0695d93e1094317374f73f7ec249750ac587
MD5: 8777960b17ac2ba80456ca98a44be025
File size: 159744 bytes

Leave a Reply