Quantcast
Viewing all articles
Browse latest Browse all 38585

BOOTMGR.SYS is Trojan Delf.hyso

We checked some samples of BOOTMGR.SYS and detected the file BOOTMGR.SYS as threat.
Remove the BOOTMGR.SYS file from your computer right now.
Removal tool: http://www.unhackme.com

Malware Analysis of BOOTMGR.SYS
Full path on a computer: C:\bootmgr.sys

Detected by UnHackMe:

Item Name: WinNsi
Author:
Related File: C:\BOOTMGR.SYS
Type: Svchost DLLs

Item Name: BOOTMGR.SYS
Author:
Related File: C:\BOOTMGR.SYS
Type: Multi AV Detected Files

Removal Results: Success
Number of reboot: 1

BOOTMGR.SYS is known as:

Trojan.Delf.hyso, Mal.Behav-363, Backdoor.Delf.RAN, a variant of Win32.Delf.OES, W32.Delf.OES

BOOTMGR.SYS hash:

  • MD5: a38f948e4d487342a53a3922919a0ea5
The file tries to connect to the dangerous web site.
How to quickly detect BOOTMGR.SYS presence?
Image may be NSFW.
Clik here to view.
Registry:
  • HKLM\System\CurrentControlSet\Services\WinNsi\Parameters\ServiceDll: “C:\bootmgr.sys”
  • HKLM\System\CurrentControlSet\Services\WinNsi\Type: 0×00000120
  • HKLM\System\CurrentControlSet\Services\WinNsi\Start: 0×00000002
  • HKLM\System\CurrentControlSet\Services\WinNsi\ErrorControl: 0×00000000
  • HKLM\System\CurrentControlSet\Services\WinNsi\ImagePath: “%SystemRoot%\System32\svchost.exe -k WinNsi”
  • HKLM\System\CurrentControlSet\Services\WinNsi\DisplayName: “Windows Network Store Interface Service”
  • HKLM\System\CurrentControlSet\Services\WinNsi\ObjectName: “LocalSystem”
  • HKLM\System\CurrentControlSet\Services\WinNsi\Description: “The service to the user mode client network notice. Stop this service will result in the loss of the network connection.”
Image may be NSFW.
Clik here to view.
Folders:
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\3PCMMHXU
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LUIIOHEM
Image may be NSFW.
Clik here to view.
Files:
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\3PCMMHXU\desktop.ini
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\3PCMMHXU\favicon[1].ico
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LUIIOHEM\desktop.ini
  • C:\bootmgr.sys


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>