4BCE0.SYS – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

4BCE0.SYS – Trojan Agent removal

File MD5 Virus Alias
4BCE0.SYS a2f2b24bd6fa13095c319f7f61c21d2f Trojan Agent
4BCE0.SYS a2f2b24bd6fa13095c319f7f61c21d2f Trojan Generic
4BCE0.SYS a2f2b24bd6fa13095c319f7f61c21d2f Trojan Downloader
4BCE0.SYS a2f2b24bd6fa13095c319f7f61c21d2f Trojan CI
4BCE0.SYS a2f2b24bd6fa13095c319f7f61c21d2f Trojan Kryptik

4BCE0.SYS size: 56832 bytes
4BCE0.SYS hash: A2F2B24BD6FA13095C319F7F61C21D2F

Created files:

%SysDir%\drivers\4bce0.sys
%Temp%\Bieg\epmo.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\4bce0\Type: 01000000
HKLM\System\CurrentControlSet\Services\4bce0\Start: 01000000
HKLM\System\CurrentControlSet\Services\4bce0\DisplayName: epmo.exe
HKLM\System\CurrentControlSet\Services\4bce0\ImagePath: %WinDir%\System32\drivers\4bce0.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Epmo: “%Temp%\Bieg\epmo.exe”

Detected by UnHackMe:

4BCE0.SYS
Default location: %SYSDIR%\DRIVERS\4BCE0.SYS

Dropper information:
MD5: 9374d607ffed0be680a648a4d454ca47
File size: 507904 bytes

Leave a Reply