Solved! Use SOUNDDRV.EXE (Trojan Tibia) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SOUNDDRV.EXE – Trojan Tibia removal

FileMD5Virus Alias
SOUNDDRV.EXE b413139409785d00e7cfc5af8eac65e2 Trojan Tibia
SOUNDDRV.EXE b413139409785d00e7cfc5af8eac65e2 Trojan SuspiciousFile
SOUNDDRV.EXE b413139409785d00e7cfc5af8eac65e2 Trojan Malware.Obscu
SOUNDDRV.EXE b413139409785d00e7cfc5af8eac65e2 Trojan Generic
SOUNDDRV.EXE b413139409785d00e7cfc5af8eac65e2 Trojan Xema
SOUNDDRV.EXE b413139409785d00e7cfc5af8eac65e2 Trojan Agent

SOUNDDRV.EXE size: 38400 bytes
SOUNDDRV.EXE hash: B413139409785D00E7CFC5AF8EAC65E2

Created files:

%WinDir%\sounddrv.exe
%Temp%\52DC6A.dmp

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\SoundCardDriver\Type: 10010000
HKLM\System\CurrentControlSet\Services\SoundCardDriver\Start: 02000000
HKLM\System\CurrentControlSet\Services\SoundCardDriver\DisplayName: SystemSound
HKLM\System\CurrentControlSet\Services\SoundCardDriver\ImagePath: %WinDir%\sounddrv.exe

Detected by UnHackMe:

SOUNDDRV.EXE
Default location: %WinDir%\SOUNDDRV.EXE

Dropper information:
MD5: b413139409785d00e7cfc5af8eac65e2
File size: 38400 bytes

Leave a Reply