Solved! Use CORELOAD.SYS (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CORELOAD.SYS – Trojan Artemis removal

FileMD5Virus Alias
CORELOAD.SYS 3f60915ce16ab5cf0116922c8aa1c1aa Trojan Artemis
CORELOAD.SYS 3f60915ce16ab5cf0116922c8aa1c1aa Trojan Downloader
CORELOAD.SYS 3f60915ce16ab5cf0116922c8aa1c1aa Trojan Agent
CORELOAD.SYS 3f60915ce16ab5cf0116922c8aa1c1aa Trojan StartPage

CORELOAD.SYS size: 362496 bytes
CORELOAD.SYS hash: 3F60915CE16AB5CF0116922C8AA1C1AA

Created files:

%WinDir%\he1p
%SysDir%\CoreLoad\CoreLoad.sys
%SysDir%\miniie\MiniIE.exe
%SysDir%\miniie\svchost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\CoreLoad\Type: 01000000
HKLM\System\CurrentControlSet\Services\CoreLoad\Start: 03000000
HKLM\System\CurrentControlSet\Services\CoreLoad\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\CoreLoad\Info: 504B0304055852234000000020882CAE7A9F658A0A550DA683839E78199FEBA07F167D81076863E862ADD4151A42CEFFD9B7C501346A333AD7246A53A97662D28679ECEE2BF6A2EFAE7E3FD172442877
HKLM\System\CurrentControlSet\Services\CoreLoad\ImagePath: \??\%WinDir%\System32\CoreLoad\CoreLoad.sys

Detected by UnHackMe:

CORELOAD.SYS
Default location: %SYSDIR%\CORELOAD\CORELOAD.SYS

Dropper information:
MD5: 63d001227b322e2036798f00a55aa09c
File size: 1339392 bytes

Leave a Reply