4B200.SYS – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

4B200.SYS – Trojan Artemis removal

FileMD5Virus Alias
4B200.SYS 0b17dd039e8a9370bc459fd6b9031c7a Trojan Artemis
4B200.SYS 0b17dd039e8a9370bc459fd6b9031c7a Trojan SuspiciousFile
4B200.SYS 0b17dd039e8a9370bc459fd6b9031c7a Trojan Generic
4B200.SYS 0b17dd039e8a9370bc459fd6b9031c7a Trojan Downloader
4B200.SYS 0b17dd039e8a9370bc459fd6b9031c7a Trojan CI
4B200.SYS 0b17dd039e8a9370bc459fd6b9031c7a Trojan Agent

4B200.SYS size: 33024 bytes
4B200.SYS hash: 0B17DD039E8A9370BC459FD6B9031C7A

Created files:

%SysDir%\drivers\4b200.sys
%Temp%\Yqib\ziat.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\4b200\Type: 01000000
HKLM\System\CurrentControlSet\Services\4b200\Start: 01000000
HKLM\System\CurrentControlSet\Services\4b200\DisplayName: ziat.exe
HKLM\System\CurrentControlSet\Services\4b200\ImagePath: %WinDir%\System32\drivers\4b200.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Ziat: “%Temp%\Yqib\ziat.exe”

Detected by UnHackMe:

4B200.SYS
Default location: %SYSDIR%\DRIVERS\4B200.SYS

Dropper information:
MD5: e281ef6855eca55f0e21ed2321102e02
File size: 723968 bytes

Leave a Reply