Home Malware Programs Trojans PLAY_MP3 Trojan

PLAY_MP3 Trojan

Posted: September 22, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 14
First Seen: September 22, 2011
Last Seen: October 23, 2020
OS(es) Affected: Windows

PLAY_MP3 Trojan is a malicious Trojan created by hackers to enable remote attackers obtain access to the infected computer system. PLAY_MP3 Trojan spreads via peer-to-peer file sharing networks and infected files, or may come bundled with other malware threats in a try to monitor the targeted PC system.. PLAY_MP3 Trojan may distribute annoying pop-up ads and install additional applications from the Internet. Uninstall PLAY_MP3 Trojan before it harms your machine.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\windows\system32\[RANDOM NAME].exe of PLAY_MP3 Trojan File name: c:\windows\system32\[RANDOM NAME].exe of PLAY_MP3 Trojan
Mime Type: unknown/exe of PLAY_MP3 Trojan
Group: Malware file
%LocalAppData%\.dll of PLAY_MP3 Trojan File name: %LocalAppData%\.dll of PLAY_MP3 Trojan
Mime Type: unknown/dll of PLAY_MP3 Trojan
Group: Malware file
%Temp%\.dll File name: %Temp%\.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\ malicious key of PLAY_MP3 TrojanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'HKEY_CURRENT_USER \Software \Microsoft\ Windows\ CurrentVersion\ Policies\ Explorer\Run\ malicious key of PLAY_MP3 TrojanHKEY_CURRENT_USER\ Software\ Microsoft \Windows\ CurrentVersion\Explorer\ShellFolders Startup="C:\windows/start menu/programs\startup
Loading...