CLIPSRV.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CLIPSRV.EXE – Trojan Downloader removal

FileMD5Virus Alias
CLIPSRV.EXE 0a1ffc69a4f27d1c7393cb117764093c Trojan Downloader
CLIPSRV.EXE 0a1ffc69a4f27d1c7393cb117764093c Trojan WS.Reputation
CLIPSRV.EXE 0a1ffc69a4f27d1c7393cb117764093c Trojan Eldorado
CLIPSRV.EXE 0a1ffc69a4f27d1c7393cb117764093c Trojan ZBot

CLIPSRV.EXE size: 365568 bytes
CLIPSRV.EXE hash: 0A1FFC69A4F27D1C7393CB117764093C

Created files:

C:\clipsrv.exe
%WinDir%\System\cmstp.exe
%WinDir%\System32\drivers\mstsc.exe
%TEMP%\logman.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\CmSTP: %WinDir%\System\cmstp.exe /waitservice
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ClipSrv: \clipsrv.exe /waitservice
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\load: %TEMP%\logman.exe

Detected by UnHackMe:

CLIPSRV.EXE
Default location: C:\CLIPSRV.EXE

Dropper information:
MD5: 0a1ffc69a4f27d1c7393cb117764093c
File size: 365568 bytes

Leave a Reply