31A3FF.SYS – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

31A3FF.SYS – Trojan Downloader removal

FileMD5Virus Alias
31A3FF.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Downloader
31A3FF.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan SuspiciousFile
31A3FF.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Generic
31A3FF.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan CI
31A3FF.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Agent
31A3FF.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Kryptik

31A3FF.SYS size: 33920 bytes
31A3FF.SYS hash: 0A6701E5A99A51F36E033FF38C43DBA8

Created files:

%SysDir%\drivers\31a3ff.sys
%Temp%\Cuti\hada.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\31a3ff\Type: 01000000
HKLM\System\CurrentControlSet\Services\31a3ff\Start: 01000000
HKLM\System\CurrentControlSet\Services\31a3ff\DisplayName: hada.exe
HKLM\System\CurrentControlSet\Services\31a3ff\ImagePath: %WinDir%\System32\drivers\31a3ff.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Hada: “%Temp%\Cuti\hada.exe”

Detected by UnHackMe:

31A3FF.SYS
Default location: %SYSDIR%\DRIVERS\31A3FF.SYS

Dropper information:
MD5: c22fab7a8bbcef4655b9af2b7c505382
File size: 591360 bytes

Leave a Reply