D20CF.SYS – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

D20CF.SYS – Trojan Artemis removal

FileMD5Virus Alias
D20CF.SYS 5b4f803464b3c1027358ac05197a9315 Trojan Artemis
D20CF.SYS 5b4f803464b3c1027358ac05197a9315 Trojan SuspiciousFile
D20CF.SYS 5b4f803464b3c1027358ac05197a9315 Trojan Generic
D20CF.SYS 5b4f803464b3c1027358ac05197a9315 Trojan Downloader
D20CF.SYS 5b4f803464b3c1027358ac05197a9315 Trojan CI
D20CF.SYS 5b4f803464b3c1027358ac05197a9315 Trojan Crypt

D20CF.SYS size: 33024 bytes
D20CF.SYS hash: 5B4F803464B3C1027358AC05197A9315

Created files:

%SysDir%\drivers\d20cf.sys
%Temp%\Rimuy\ezize.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\d20cf\Type: 01000000
HKLM\System\CurrentControlSet\Services\d20cf\Start: 01000000
HKLM\System\CurrentControlSet\Services\d20cf\DisplayName: ezize.exe
HKLM\System\CurrentControlSet\Services\d20cf\ImagePath: %WinDir%\System32\drivers\d20cf.sys

Detected by UnHackMe:

D20CF.SYS
Default location: %SYSDIR%\DRIVERS\D20CF.SYS

Dropper information:
MD5: 68b349631c76175a4a3c153ad83b67e9
File size: 664576 bytes

Leave a Reply