AHNURLA.SYS – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

AHNURLA.SYS – Trojan Agent removal

FileMD5Virus Alias
AHNURLA.SYS f38e3317bac9fa801a2b09379a0f4e6c Trojan Agent
AHNURLA.SYS f38e3317bac9fa801a2b09379a0f4e6c Trojan Generic
AHNURLA.SYS f38e3317bac9fa801a2b09379a0f4e6c Trojan CI

AHNURLA.SYS size: 36736 bytes
AHNURLA.SYS hash: F38E3317BAC9FA801A2B09379A0F4E6C

Created files:

C:\175000.dll
C:\windows\svchost.exe
C:\windows\system32\drivers\ahnurla.sys
C:\windows\system32\RpcSvc.psd
C:\windows\temp\temp1.exe
C:\windows\temp\temp2.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\ahnurla\Type: 01000000
HKLM\System\CurrentControlSet\Services\ahnurla\Start: 02000000
HKLM\System\CurrentControlSet\Services\ahnurla\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\ahnurla\DisplayName: ahnurla
HKLM\System\CurrentControlSet\Services\ahnurla\ImagePath: %WinDir%\System32\drivers\ahnurla.sys
HKLM\System\CurrentControlSet\Services\RemoteAccess\RouterManagers\Ip\DLLPath: 43003A005C003100370035003000300030002E0064006C006C000000
HKLM\System\CurrentControlSet\Services\RpcSvc\Type: 10010000
HKLM\System\CurrentControlSet\Services\RpcSvc\Start: 02000000
HKLM\System\CurrentControlSet\Services\RpcSvc\DisplayName: Remote Procedure Call (RPC) Service
HKLM\System\CurrentControlSet\Services\RpcSvc\ImagePath: %SystemRoot%\System32\svchost.exe -k imgsvc

Detected by UnHackMe:

AHNURLA.SYS
Default location: %SYSDIR%\DRIVERS\AHNURLA.SYS

Dropper information:
MD5: cf3c356161faef259e7510950c9587a1
File size: 247304 bytes

Leave a Reply