GIU.SYS – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

GIU.SYS – Trojan Agent removal

FileMD5Virus Alias
GIU.SYS 2348b83571e6fede8fbbefe54d7a5891 Trojan Agent
GIU.SYS 2348b83571e6fede8fbbefe54d7a5891 Trojan SuspiciousFile

GIU.SYS size: 6144 bytes
GIU.SYS hash: 2348B83571E6FEDE8FBBEFE54D7A5891

Created files:

%SysDir%\drivers\giu.sys
%TEMP%\tmpHKY5\userlog.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\run\ZDYX: %TEMP%\tmpHKY5\userlog.exe
HKLM\System\CurrentControlSet\Services\My_DriverLinkName_test\Type: 01000000
HKLM\System\CurrentControlSet\Services\My_DriverLinkName_test\Start: 03000000
HKLM\System\CurrentControlSet\Services\My_DriverLinkName_test\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\My_DriverLinkName_test\DisplayName: My_DriverLinkName_test
HKLM\System\CurrentControlSet\Services\My_DriverLinkName_test\ImagePath: %WinDir%\System32\drivers\giu.sys

Detected by UnHackMe:

GIU.SYS
Default location: %SYSDIR%\DRIVERS\GIU.SYS

Dropper information:
MD5: 13ceb0acbafabfb0b015cd6262b37b54
File size: 1662976 bytes

Leave a Reply