Threat Database Malware Win32/Ptcasino

Win32/Ptcasino

By Sumo3000 in Malware

Win32/Ptcasino is an online gambling related infection, which is dropped through the vulnerabilities of online games websites and steals targeted user's personal details. Win32/Ptcasino, being gambling related infection does not limit the virus payload to steal data important for players of online games only. Peculiarities of information exchange between website running online games allow to gain extended access to a range of affected computers and to retrieve various information, turn the computer into spybot, etc. Win32/Ptcasino usually proliferates via online card games, such as Pocker, but also can be sent otherwise. Removal of Win32/Ptcasino is recommended not for online gamers only.

File System Details

Win32/Ptcasino may create the following file(s):
# File Name Detections
1. %Documents and Settings%\All Users\Application Data\iosejgfse.dll
2. %Documents and Settings%\[UserName]\Start Menu\Buy.lnk

Registry Details

Win32/Ptcasino may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Paladin Antivirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations 'LowRiskFileTypes' = '.exe'
HKEY_CURRENT_USER\Software\Malware Defense
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments 'SaveZoneInformation' = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce 'SelfdelNT'

Trending

Most Viewed

Loading...