Solved! Use AGROIO.SYS (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

AGROIO.SYS – Trojan Artemis removal

File MD5 Virus Alias
AGROIO.SYS 34131dde9f7d301ce0a29f5bea66c3f6 Trojan Artemis
AGROIO.SYS 34131dde9f7d301ce0a29f5bea66c3f6 Trojan SuspiciousFile
AGROIO.SYS 34131dde9f7d301ce0a29f5bea66c3f6 Trojan Generic
AGROIO.SYS 34131dde9f7d301ce0a29f5bea66c3f6 Trojan Dulom
AGROIO.SYS 34131dde9f7d301ce0a29f5bea66c3f6 Trojan CI
AGROIO.SYS 34131dde9f7d301ce0a29f5bea66c3f6 Trojan Agent

AGROIO.SYS size: 25216 bytes
AGROIO.SYS hash: 34131DDE9F7D301CE0A29F5BEA66C3F6

Created files:

%SysDir%\drivers\agroio.sys
%SysDir%\drivers\hp3900.sys
%AppData%\Macromidia\alg.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\agroio\Type: 01000000
HKLM\System\CurrentControlSet\Services\agroio\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\agroio\DisplayName: agroio
HKLM\System\CurrentControlSet\Services\agroio\ImagePath: %WinDir%\System32\drivers\agroio.sys
HKLM\System\CurrentControlSet\Services\hp3900\Type: 01000000
HKLM\System\CurrentControlSet\Services\hp3900\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\hp3900\DisplayName: hp3900
HKLM\System\CurrentControlSet\Services\hp3900\ImagePath: %WinDir%\System32\drivers\hp3900.sys
HKLM\System\CurrentControlSet\Services\hp3900\Group: Boot Bus Extender
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\alg: %AppData%\Macromidia\alg.exe

Detected by UnHackMe:

AGROIO.SYS
Default location: %SYSDIR%\DRIVERS\AGROIO.SYS

Dropper information:
MD5: d4bc6b1d5b86b0138bef766ba7de2d70
File size: 986112 bytes

Leave a Reply