Threat Database Trojans Trojan.Cidox.C

Trojan.Cidox.C

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 4
First Seen: May 8, 2014
Last Seen: February 18, 2022
OS(es) Affected: Windows

Trojan.Cidox.C is a Trojan that steals information from the attacked PC. When executed, Trojan.Cidox.C creates potentially infected files. Trojan.Cidox.C creates the registry entries. Trojan.Cidox.C modifies the Initial Program Loader (IPL) of the NTFS boot sector so it can run malevolent code directly from the disk. Trojan.Cidox.C writes its malevolent components into the encrypted file. Trojan.Cidox.C then deletes itself and restarts the corrupted PC. Trojan.Cidox.C loads the infectious driver component into memory through the modified NTFS boot sector's IPL upon boot-up. Trojan.Cidox.C may log keystrokes and save the stolen details in its own virtual file system. Trojan.Cidox.C phones home by creating an URL and completing the web address by adding the particular string '_hello.php?param=[DATA]'.

File System Details

Trojan.Cidox.C may create the following file(s):
# File Name Detections
1. %System%\drivers\yurip.sys
2. %System%\drivers\jwivs.sys
3. %System%\[RANDOM CHARACTERS].bin

Registry Details

Trojan.Cidox.C may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\yurip
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\jwivs

Trending

Most Viewed

Loading...