Win32:BHO-RJ

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

Win32:BHO-RJ also known as not-a-virus:AdWare.Win32.BHO.ckn, BackDoor.Bho.6.

Malware Analysis of Win32:BHO-RJ – DDR7XM.DLL

Created files:

%SYSDIR%\D9XDR.DLL
%SYSDIR%\DDR7XM.DLL
%SYSDIR%\PRXSMR.DLL

Autostart registry keys:

HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\1: “%SYSDIR%\MRCMGR.EXE”
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\USERINIT: “%SYSDIR%\USERINIT.EXE,%SYSDIR%\MRCMGR.EXE,”

Detected by UnHackMe:

DDR7XM.DLL
Default location: %SYSDIR%\DDR7XM.DLL

Dropper hash(md5): 25f621397336d35bc8d28dde899c11f2

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

1
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera