Solved! Use WINDEV-72C9-1D3A.SYS (Trojan (Suspicious File)) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

WINDEV-72C9-1D3A.SYS – Trojan (Suspicious File) removal

File MD5 Virus Alias
WINDEV-72C9-1D3A.SYS 187a09277b6ff075c4f4350242c3b3c9 Trojan (Suspicious File)

WINDEV-72C9-1D3A.SYS size: 152192 bytes
WINDEV-72C9-1D3A.SYS hash: 187A09277B6FF075C4F4350242C3B3C9

Created files:

%SysDir%\windev-72c9-1d3a.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\windev-72c9-1d3a\Type: 01000000
HKLM\System\CurrentControlSet\Services\windev-72c9-1d3a\Start: 02000000
HKLM\System\CurrentControlSet\Services\windev-72c9-1d3a\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\windev-72c9-1d3a\DisplayName: windev-72c9-1d3a
HKLM\System\CurrentControlSet\Services\windev-72c9-1d3a\ImagePath: %WinDir%\System32\windev-72c9-1d3a.sys

Detected by UnHackMe:

WINDEV-72C9-1D3A.SYS
Default location: %SYSDIR%\WINDEV-72C9-1D3A.SYS

Dropper information:
MD5: d683ac10642aabe30d1c3f2ea6e9e2b0
File size: 133197 bytes

Leave a Reply