264901.SYS – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

264901.SYS – Trojan Agent removal

FileMD5Virus Alias
264901.SYS a2f2b24bd6fa13095c319f7f61c21d2f Trojan Agent
264901.SYS a2f2b24bd6fa13095c319f7f61c21d2f Trojan Generic
264901.SYS a2f2b24bd6fa13095c319f7f61c21d2f Trojan Downloader
264901.SYS a2f2b24bd6fa13095c319f7f61c21d2f Trojan CI
264901.SYS a2f2b24bd6fa13095c319f7f61c21d2f Trojan Kryptik

264901.SYS size: 56832 bytes
264901.SYS hash: A2F2B24BD6FA13095C319F7F61C21D2F

Created files:

%SysDir%\drivers\264901.sys
%WinDir%\Temp\Ohza\udecbu.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\264901\Type: 01000000
HKLM\System\CurrentControlSet\Services\264901\Start: 01000000
HKLM\System\CurrentControlSet\Services\264901\DisplayName: udecbu.exe
HKLM\System\CurrentControlSet\Services\264901\ImagePath: %WinDir%\System32\drivers\264901.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Udecbu: %WinDir%\Temp\Ohza\udecbu.exe

Detected by UnHackMe:

264901.SYS
Default location: %SYSDIR%\DRIVERS\264901.SYS

Dropper information:
MD5: 2b0626fcde37a308690e0dc09eb9d58a
File size: 493568 bytes

Leave a Reply