C72ED.SYS – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

C72ED.SYS – Trojan Downloader removal

FileMD5Virus Alias
C72ED.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Downloader
C72ED.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan SuspiciousFile
C72ED.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Generic
C72ED.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan CI
C72ED.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Agent
C72ED.SYS 0a6701e5a99a51f36e033ff38c43dba8 Trojan Kryptik

C72ED.SYS size: 33920 bytes
C72ED.SYS hash: 0A6701E5A99A51F36E033FF38C43DBA8

Created files:

%SysDir%\drivers\c72ed.sys
%Temp%\Xaakeg\riwov.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\c72ed\Type: 01000000
HKLM\System\CurrentControlSet\Services\c72ed\Start: 01000000
HKLM\System\CurrentControlSet\Services\c72ed\DisplayName: riwov.exe
HKLM\System\CurrentControlSet\Services\c72ed\ImagePath: %WinDir%\System32\drivers\c72ed.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Riwov: “%Temp%\Xaakeg\riwov.exe”

Detected by UnHackMe:

C72ED.SYS
Default location: %SYSDIR%\DRIVERS\C72ED.SYS

Dropper information:
MD5: 2fceee5525a72ea6681112e77ad86ac2
File size: 589824 bytes

Leave a Reply