6F1D4A07.SYS – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

6F1D4A07.SYS – Trojan Artemis removal

FileMD5Virus Alias
6F1D4A07.SYS 7d78a9edebef9ac9c67c667e88f85134 Trojan Artemis
6F1D4A07.SYS 7d78a9edebef9ac9c67c667e88f85134 Trojan Genome
6F1D4A07.SYS 7d78a9edebef9ac9c67c667e88f85134 Trojan CI
6F1D4A07.SYS 7d78a9edebef9ac9c67c667e88f85134 Trojan Graftor
6F1D4A07.SYS 7d78a9edebef9ac9c67c667e88f85134 Rootkit TDSS

6F1D4A07.SYS size: 9104 bytes
6F1D4A07.SYS hash: 7D78A9EDEBEF9AC9C67C667E88F85134

Created files:

%SysDir%\39343B0C.sys
%SysDir%\6F1D4A07.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Control\Keyboard Layouts\E0010409\Layout File: KBDUS.DLL
HKLM\System\CurrentControlSet\Control\Keyboard Layouts\E0010409\Layout Text: 4D7072C8
HKLM\System\CurrentControlSet\Services\39343B0C\Type: 01000000
HKLM\System\CurrentControlSet\Services\39343B0C\ImagePath: 730079007300740065006D00330032005C00330039003300340033004200300043002E007300790073000000
HKLM\System\CurrentControlSet\Services\39343B0C\Group: 42006100730065000000
HKLM\System\CurrentControlSet\Services\6F1D4A07\Type: 01000000
HKLM\System\CurrentControlSet\Services\6F1D4A07\Start: 02000000
HKLM\System\CurrentControlSet\Services\6F1D4A07\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\6F1D4A07\DisplayName: 6F1D4A07
HKLM\System\CurrentControlSet\Services\6F1D4A07\ImagePath: %WinDir%\System32\6F1D4A07.sys

Detected by UnHackMe:

6F1D4A07.SYS
Default location: %SYSDIR%\6F1D4A07.SYS

Dropper information:
MD5: 4396d87472fcdce080424b7d3bc4f8ef
File size: 124928 bytes

Leave a Reply