CLIPSRV.EXE – Trojan Small

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CLIPSRV.EXE – Trojan Small removal

FileMD5Virus Alias
CLIPSRV.EXE 03d370bf9d860645cbbe67d515150f57 Trojan Small
CLIPSRV.EXE 03d370bf9d860645cbbe67d515150f57 Trojan Artemis
CLIPSRV.EXE 03d370bf9d860645cbbe67d515150f57 Trojan Generic
CLIPSRV.EXE 03d370bf9d860645cbbe67d515150f57 Trojan Eldorado
CLIPSRV.EXE 03d370bf9d860645cbbe67d515150f57 Trojan Downloader
CLIPSRV.EXE 03d370bf9d860645cbbe67d515150f57 Trojan Agent

CLIPSRV.EXE size: 472064 bytes
CLIPSRV.EXE hash: 03D370BF9D860645CBBE67D515150F57

Created files:

%WinDir%\System\rsvp.exe
%UserProfile%\Local Settings\Application Data\Microsoft\cisvc.exe
%UserProfile%\Local Settings\Application Data\Microsoft\clipsrv.exe
%UserProfile%\Local Settings\Application Data\smss.exe
%TEMP%\Twain002.Mtx
%WinDir%\winlogon.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\cisvc: %Local AppData%\Microsoft\cisvc.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Session Manager: %WinDir%\System32\config\SYSTEM~1\LOCALS~1\APPLIC~1\smss.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ClipSrv: %Local AppData%\Microsoft\clipsrv.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WinLogon: %WinDir%\winlogon.exe

Detected by UnHackMe:

CLIPSRV.EXE
Default location: %LOCAL APPDATA%\MICROSOFT\CLIPSRV.EXE

Dropper information:
MD5: 03d370bf9d860645cbbe67d515150f57
File size: 472064 bytes

Leave a Reply