4CB81.SYS – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

4CB81.SYS – Trojan Artemis removal

FileMD5Virus Alias
4CB81.SYS e2cee1c1a9a2e7a89341b35e99a494c4 Trojan Artemis
4CB81.SYS e2cee1c1a9a2e7a89341b35e99a494c4 Trojan SuspiciousFile
4CB81.SYS e2cee1c1a9a2e7a89341b35e99a494c4 Trojan Generic
4CB81.SYS e2cee1c1a9a2e7a89341b35e99a494c4 Trojan Downloader
4CB81.SYS e2cee1c1a9a2e7a89341b35e99a494c4 Trojan ZBot
4CB81.SYS e2cee1c1a9a2e7a89341b35e99a494c4 Trojan Kryptik

4CB81.SYS size: 56704 bytes
4CB81.SYS hash: E2CEE1C1A9A2E7A89341B35E99A494C4

Created files:

%SysDir%\drivers\4cb81.sys
%Temp%\Saduov\xipiyb.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\4cb81\Type: 01000000
HKLM\System\CurrentControlSet\Services\4cb81\Start: 01000000
HKLM\System\CurrentControlSet\Services\4cb81\DisplayName: xipiyb.exe
HKLM\System\CurrentControlSet\Services\4cb81\ImagePath: %WinDir%\System32\drivers\4cb81.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Xipiyb: “%Temp%\Saduov\xipiyb.exe”

Detected by UnHackMe:

4CB81.SYS
Default location: %SYSDIR%\DRIVERS\4CB81.SYS

Dropper information:
MD5: 08f202f9b054dd7a2353ed1658e51a84
File size: 500224 bytes

Leave a Reply