DOWIRE.SYS – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DOWIRE.SYS – Trojan Agent removal

FileMD5Virus Alias
DOWIRE.SYS 5a0751f200a42271278101e145944ecd Trojan Agent
DOWIRE.SYS 5a0751f200a42271278101e145944ecd Trojan JboxGeneric
DOWIRE.SYS 5a0751f200a42271278101e145944ecd Trojan Eldorado
DOWIRE.SYS 5a0751f200a42271278101e145944ecd Trojan Downloader
DOWIRE.SYS 5a0751f200a42271278101e145944ecd Worm AMN
DOWIRE.SYS 5a0751f200a42271278101e145944ecd Trojan Jbox

DOWIRE.SYS size: 16384 bytes

Created files:

%SysDir%\11.exe
%SysDir%\DOWIRE.sys
%SysDir%\wanzhou.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\DOWIRE\Type: 01000000
HKLM\System\CurrentControlSet\Services\DOWIRE\Start: 03000000
HKLM\System\CurrentControlSet\Services\DOWIRE\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\DOWIRE\DisplayName: DOWIRE
HKLM\System\CurrentControlSet\Services\DOWIRE\ImagePath: C:\Windows\System32\DOWIRE.sys

Detected by UnHackMe:

DOWIRE.SYS
Default location: %SYSDIR%\DOWIRE.SYS
Dropper information:
MD5: c2fdd7c4e1cda3434986be7be434ecee
File size: 464650 bytes

Leave a Reply