regtoro.sys – Trojan Banker

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

regtoro.sys – Trojan Banker removal

FileVirus Alias
regtoro.sys Trojan Banker
regtoro.sys Trojan Banload
regtoro.sys Trojan Dadobra
regtoro.sys Trojan Agent
regtoro.sys Trojan Bancos
regtoro.sys Trojan Downloader.Generic

Created files:

C:\Windows\system32\drivers\regtoro.sys – Trojan Banker
C:\Windows\Tcp_IP.exe – Trojan Banker

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run : C:\Windows\Tcp_IP.exe

Detected by UnHackMe:

regtoro.sys
Default location: C:\Windows\system32\drivers\regtoro.sys

Dropper information:
SHA256: 525062ddcc088e2bd6343e0a7251cf847da7a0f1959b7bf3316beaa5e6197621
SHA1: bafea12aafb94436f2d8ae1a3c9659abce3d249b
MD5: f260cf1cab5a7dad1d80e2430038645b
File size: 2115584 bytes

Leave a Reply