Home Malware Programs Trojans Trojan.Cidox.C

Trojan.Cidox.C

Posted: May 8, 2014

Threat Metric

Threat Level: 9/10
Infected PCs: 12
First Seen: May 8, 2014
Last Seen: December 2, 2024
OS(es) Affected: Windows



Trojan.Cidox.C is a Trojan that steals information from the affected computer. When Trojan.Cidox.C is executed, it creates potentially malicious files. Trojan.Cidox.C creates the registry entries. Trojan.Cidox.C modifies the NTFS boot sector's Initial Program Loader (IPL) so it can run malicious code directly from the disk. Trojan.Cidox.C writes its malicious components into the encrypted file. Trojan.Cidox.C then deletes itself and reboots the attacked computer system. Trojan.Cidox.C loads the malicious driver component into memory through the modified NTFS boot sector's IPL upon startup. Trojan.Cidox.C may log keystrokes and save the stolen information in its own virtual file system. Trojan.Cidox.C phones home by generating a domain name and completing the URL by attaching the specific string '_hello.php?param=[DATA]'.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%System%\drivers\yurip.sys File name: %System%\drivers\yurip.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\drivers\jwivs.sys File name: %System%\drivers\jwivs.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\[RANDOM CHARACTERS].bin File name: %System%\[RANDOM CHARACTERS].bin
File type: Binary File
Mime Type: unknown/bin
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\yuripHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\jwivs
Loading...