PASTTUYT4.SYS – Trojan BadReputation

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

PASTTUYT4.SYS – Trojan BadReputation removal

FileMD5Virus Alias
PASTTUYT4.SYS 974eea16ffb1aa01c53d36b4a6d6259d Trojan BadReputation

PASTTUYT4.SYS size: 3584 bytes
PASTTUYT4.SYS hash: 974EEA16FFB1AA01C53D36B4A6D6259D

Created files:

%WinDir%\Internet Explorer.exe
%SysDir%\mydri.sys
%SysDir%\PasttUyT4.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\baby\Type: 01000000
HKLM\System\CurrentControlSet\Services\baby\Start: 03000000
HKLM\System\CurrentControlSet\Services\baby\DisplayName: baby
HKLM\System\CurrentControlSet\Services\baby\ImagePath: %WinDir%\System32\PasttUyT4.sys
HKLM\System\CurrentControlSet\Services\DBKDRVR54\Type: 01000000
HKLM\System\CurrentControlSet\Services\DBKDRVR54\Start: 03000000
HKLM\System\CurrentControlSet\Services\DBKDRVR54\DisplayName: DBKDRVR54
HKLM\System\CurrentControlSet\Services\DBKDRVR54\ImagePath: %WinDir%\System32\.\mydri.sys

Detected by UnHackMe:

PASTTUYT4.SYS
Default location: %SYSDIR%\PASTTUYT4.SYS

Dropper information:
MD5: 6f8cbcb5b26d80717cb6065023f11d36
File size: 1556480 bytes

Leave a Reply