Trojan Crypt – winlogen.exe – b2f2636f9a6308797a450d63110dc78e

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Crypt
Also known as: Trojan Delf
SHA256: 85441e66c838c2968d78f829c175e3f91780fbd1b594a14b29bae98aaedeb0a8
SHA1: 25be663e1eb84c5c9dc5dbd4784142e1d88d6edc
MD5: b2f2636f9a6308797a450d63110dc78e
File size: 414033 bytes

Created files:

C:\system32\winlogen.exe – Trojan Crypt
%Temp%\Stage1.exe – Trojan Crypt
%Temp%\Stage2.exe – Trojan Crypt

Trojan Crypt created autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit: %WinDir%\System32\userinit.exe,C:\System32\winlogen.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\winlogen: C:\System32\winlogen.exe

Leave a Reply