Solved! Use CORELOAD.SYS (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CORELOAD.SYS – Trojan Artemis removal

FileMD5Virus Alias
CORELOAD.SYS 3f60915ce16ab5cf0116922c8aa1c1aa Trojan Artemis
CORELOAD.SYS 3f60915ce16ab5cf0116922c8aa1c1aa Trojan Downloader
CORELOAD.SYS 3f60915ce16ab5cf0116922c8aa1c1aa Trojan Agent
CORELOAD.SYS 3f60915ce16ab5cf0116922c8aa1c1aa Trojan StartPage

CORELOAD.SYS size: 362496 bytes
CORELOAD.SYS hash: 3F60915CE16AB5CF0116922C8AA1C1AA

Created files:

%SysDir%\CoreLoad\CoreLoad.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\CoreLoad\Type: 01000000
HKLM\System\CurrentControlSet\Services\CoreLoad\Start: 03000000
HKLM\System\CurrentControlSet\Services\CoreLoad\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\CoreLoad\Info: 504B0304C1C7C56B40000000F01D292AED6274FD5AC09DFA704EE0D16468332A86A0623C26955CDD49820D58EBCB330790215F8E6E59844166CC46A97B3CA8F1A180872DADEC7375677CC01231D6D661
HKLM\System\CurrentControlSet\Services\CoreLoad\ImagePath: \??\%WinDir%\System32\CoreLoad\CoreLoad.sys

Detected by UnHackMe:

CORELOAD.SYS
Default location: %SYSDIR%\CORELOAD\CORELOAD.SYS

Dropper information:
MD5: cf6d599ecde16b105c958e5c46011fae
File size: 1339392 bytes

Leave a Reply