3D641D.SYS – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

3D641D.SYS – Trojan Artemis removal

FileMD5Virus Alias
3D641D.SYS 4dd92d1bd1ccc825adb47e0c57746e94 Trojan Artemis
3D641D.SYS 4dd92d1bd1ccc825adb47e0c57746e94 Trojan Generic
3D641D.SYS 4dd92d1bd1ccc825adb47e0c57746e94 Trojan Downloader
3D641D.SYS 4dd92d1bd1ccc825adb47e0c57746e94 Trojan CI

3D641D.SYS size: 57216 bytes
3D641D.SYS hash: 4DD92D1BD1CCC825ADB47E0C57746E94

Created files:

%SysDir%\drivers\3d641d.sys
%Temp%\Tigi\koox.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\3d641d\Type: 01000000
HKLM\System\CurrentControlSet\Services\3d641d\Start: 01000000
HKLM\System\CurrentControlSet\Services\3d641d\DisplayName: koox.exe
HKLM\System\CurrentControlSet\Services\3d641d\ImagePath: %WinDir%\System32\drivers\3d641d.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Koox: “%Temp%\Tigi\koox.exe”

Detected by UnHackMe:

3D641D.SYS
Default location: %SYSDIR%\DRIVERS\3D641D.SYS

Dropper information:
MD5: ee9befdedf7314586cc2196822ca618e
File size: 601114 bytes

Leave a Reply