CLP220.SYS – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CLP220.SYS – Trojan Artemis removal

FileMD5Virus Alias
CLP220.SYS 827c7091daf5f8a7921f6163ceb479b9 Trojan Artemis
CLP220.SYS 827c7091daf5f8a7921f6163ceb479b9 Trojan SuspiciousFile
CLP220.SYS 827c7091daf5f8a7921f6163ceb479b9 Trojan Generic
CLP220.SYS 827c7091daf5f8a7921f6163ceb479b9 Trojan Dulom
CLP220.SYS 827c7091daf5f8a7921f6163ceb479b9 Trojan CI
CLP220.SYS 827c7091daf5f8a7921f6163ceb479b9 Trojan Agent

CLP220.SYS size: 4608 bytes
CLP220.SYS hash: 827C7091DAF5F8A7921F6163CEB479B9

Created files:

%SysDir%\drivers\basf300.sys
%SysDir%\drivers\clp220.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\basf300\Type: 01000000
HKLM\System\CurrentControlSet\Services\basf300\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\basf300\DisplayName: basf300
HKLM\System\CurrentControlSet\Services\basf300\ImagePath: %WinDir%\System32\drivers\basf300.sys
HKLM\System\CurrentControlSet\Services\clp220\Type: 01000000
HKLM\System\CurrentControlSet\Services\clp220\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\clp220\DisplayName: clp220
HKLM\System\CurrentControlSet\Services\clp220\ImagePath: %WinDir%\System32\drivers\clp220.sys
HKLM\System\CurrentControlSet\Services\clp220\Group: Boot Bus Extender
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\cssrs: \Macromidia\cssrs.exe

Detected by UnHackMe:

CLP220.SYS
Default location: %SYSDIR%\DRIVERS\CLP220.SYS

Dropper information:
MD5: e06cb8841668568dc5000ff94327698c
File size: 290304 bytes

Leave a Reply