Home Malware Programs Trojans GameThief.Win32.OnLineGames.tnys

GameThief.Win32.OnLineGames.tnys

Posted: December 22, 2010

GameThief.Win32.OnLineGames.tnys is a malicious Trojan which promotes for notorious rogue program Antivirus Scan. GameThief.Win32.OnLineGames.tnys downloads and installs Antivirus Scan onto your system with little consent. Your computer keep getting frequent fake alerts that your system is in danger and won't let you go anywhere except Antivirus Scan purchase page. This is a trap to push you to pay money for a useless product. Do not fall for this trickery and remove these threats using a reliable malware remover immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\[random]\
    2 %Temp%\[random]\[random].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter ?Enabled? = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = 'http=127.0.0.1:59274'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"HKEY_CURRENT_USER\Software\[random]
Loading...