CMSTP.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CMSTP.EXE – Trojan Downloader removal

FileMD5Virus Alias
CMSTP.EXE 0a1ffc69a4f27d1c7393cb117764093c Trojan Downloader
CMSTP.EXE 0a1ffc69a4f27d1c7393cb117764093c Trojan WS.Reputation
CMSTP.EXE 0a1ffc69a4f27d1c7393cb117764093c Trojan Eldorado
CMSTP.EXE 0a1ffc69a4f27d1c7393cb117764093c Trojan ZBot

CMSTP.EXE size: 365568 bytes
CMSTP.EXE hash: 0A1FFC69A4F27D1C7393CB117764093C

Created files:

C:\clipsrv.exe
%WinDir%\System\cmstp.exe
%WinDir%\System32\drivers\mstsc.exe
%TEMP%\logman.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\CmSTP: %WinDir%\System\cmstp.exe /waitservice
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ClipSrv: \clipsrv.exe /waitservice
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\load: %TEMP%\logman.exe

Detected by UnHackMe:

CMSTP.EXE
Default location: %WinDir%\SYSTEM\CMSTP.EXE

Dropper information:
MD5: 0a1ffc69a4f27d1c7393cb117764093c
File size: 365568 bytes

Leave a Reply