I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
296E94.SYS – Trojan Agent removal
File | MD5 | Virus Alias |
---|---|---|
296E94.SYS | a2f2b24bd6fa13095c319f7f61c21d2f | Trojan Agent |
296E94.SYS | a2f2b24bd6fa13095c319f7f61c21d2f | Trojan Generic |
296E94.SYS | a2f2b24bd6fa13095c319f7f61c21d2f | Trojan Downloader |
296E94.SYS | a2f2b24bd6fa13095c319f7f61c21d2f | Trojan CI |
296E94.SYS | a2f2b24bd6fa13095c319f7f61c21d2f | Trojan Kryptik |
296E94.SYS size: 56832 bytes
296E94.SYS hash: A2F2B24BD6FA13095C319F7F61C21D2F
Created files:
%SysDir%\drivers\296e94.sys
%WinDir%\Temp\Arin\tome.exe
Autostart registry keys:
HKLM\System\CurrentControlSet\Services\296e94\Type: 01000000
HKLM\System\CurrentControlSet\Services\296e94\Start: 01000000
HKLM\System\CurrentControlSet\Services\296e94\DisplayName: tome.exe
HKLM\System\CurrentControlSet\Services\296e94\ImagePath: %WinDir%\System32\drivers\296e94.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Tome: %WinDir%\Temp\Arin\tome.exe
Detected by UnHackMe:
296E94.SYS
Default location: %SYSDIR%\DRIVERS\296E94.SYS
Dropper information:
MD5: 2c3f9638d9d21b684d70e3c11e79b603
File size: 643584 bytes