1D3A20.SYS – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

1D3A20.SYS – Trojan Artemis removal

FileMD5Virus Alias
1D3A20.SYS 4dd92d1bd1ccc825adb47e0c57746e94 Trojan Artemis
1D3A20.SYS 4dd92d1bd1ccc825adb47e0c57746e94 Trojan Generic
1D3A20.SYS 4dd92d1bd1ccc825adb47e0c57746e94 Trojan Downloader
1D3A20.SYS 4dd92d1bd1ccc825adb47e0c57746e94 Trojan CI

1D3A20.SYS size: 57216 bytes
1D3A20.SYS hash: 4DD92D1BD1CCC825ADB47E0C57746E94

Created files:

%SysDir%\drivers\1d3a20.sys
%Temp%\Simieq\durexe.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\1d3a20\Type: 01000000
HKLM\System\CurrentControlSet\Services\1d3a20\Start: 01000000
HKLM\System\CurrentControlSet\Services\1d3a20\DisplayName: durexe.exe
HKLM\System\CurrentControlSet\Services\1d3a20\ImagePath: %WinDir%\System32\drivers\1d3a20.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Durexe: “%Temp%\Simieq\durexe.exe”

Detected by UnHackMe:

1D3A20.SYS
Default location: %SYSDIR%\DRIVERS\1D3A20.SYS

Dropper information:
MD5: 3ca68b92723ac2aea79b61fb262c01dd
File size: 407040 bytes

Leave a Reply