29AA8C.SYS – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

29AA8C.SYS – Trojan Downloader removal

FileMD5Virus Alias
29AA8C.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Downloader
29AA8C.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan SuspiciousFile
29AA8C.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Generic
29AA8C.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan CI
29AA8C.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Agent
29AA8C.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Kryptik

29AA8C.SYS size: 33920 bytes
29AA8C.SYS hash: 0A6701E5A99A51F36E033FF38C43DBA8

Created files:

%SysDir%\drivers\29aa8c.sys
%Temp%\Xoibdu\nupa.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\29aa8c\Type: 01000000
HKLM\System\CurrentControlSet\Services\29aa8c\Start: 01000000
HKLM\System\CurrentControlSet\Services\29aa8c\DisplayName: nupa.exe
HKLM\System\CurrentControlSet\Services\29aa8c\ImagePath: %WinDir%\System32\drivers\29aa8c.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Nupa: “%Temp%\Xoibdu\nupa.exe”

Detected by UnHackMe:

29AA8C.SYS
Default location: %SYSDIR%\DRIVERS\29AA8C.SYS

Dropper information:
MD5: 9f41f913ce3be0fd0dd48a1d407d683d
File size: 591360 bytes

Leave a Reply