NSAVFLT.SYS – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

NSAVFLT.SYS – Trojan Artemis removal

FileMD5Virus Alias
NSAVFLT.SYS 35db7dffb776c9bfdc13746169669b6b Trojan Artemis
NSAVFLT.SYS 35db7dffb776c9bfdc13746169669b6b Trojan Generic
NSAVFLT.SYS 35db7dffb776c9bfdc13746169669b6b Trojan CI
NSAVFLT.SYS 35db7dffb776c9bfdc13746169669b6b Worm AMN
NSAVFLT.SYS 35db7dffb776c9bfdc13746169669b6b Trojan Agent

NSAVFLT.SYS size: 14464 bytes
NSAVFLT.SYS hash: 35DB7DFFB776C9BFDC13746169669B6B

Created files:

%SysDir%\nsavflt.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\net8139\Type: 01000000
HKLM\System\CurrentControlSet\Services\net8139\Start: 02000000
HKLM\System\CurrentControlSet\Services\net8139\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\net8139\DisplayName: net8139
HKLM\System\CurrentControlSet\Services\net8139\ImagePath: %WinDir%\System32\nsavflt.sys

Detected by UnHackMe:

NSAVFLT.SYS
Default location: %SYSDIR%\NSAVFLT.SYS

Dropper information:
MD5: 5f9c57b6bd367d633517a6e58c49dc16
File size: 65024 bytes

Leave a Reply