RATDRV.SYS – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

RATDRV.SYS – Trojan Artemis removal

FileMD5Virus Alias
RATDRV.SYS 9e293ee526fb22bdefa0e0e167a764ee Trojan Artemis
RATDRV.SYS 9e293ee526fb22bdefa0e0e167a764ee Trojan BadReputation
RATDRV.SYS 9e293ee526fb22bdefa0e0e167a764ee Trojan SuspiciousFile
RATDRV.SYS 9e293ee526fb22bdefa0e0e167a764ee Trojan Generic

RATDRV.SYS size: 62592 bytes
RATDRV.SYS hash: 9E293EE526FB22BDEFA0E0E167A764EE

Created files:

C:\ratdrv.sys
C:\zwidmsra_354A0B8D30A47FA22E9EB8DC67549C99.EXE

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MsRaTool: C:\zwidmsra_354A0B8D30A47FA22E9EB8DC67549C99.EXE
HKLM\System\CurrentControlSet\Services\ratdrv.sys\Type: 01000000
HKLM\System\CurrentControlSet\Services\ratdrv.sys\Start: 03000000
HKLM\System\CurrentControlSet\Services\ratdrv.sys\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\ratdrv.sys\DisplayName: ratdrv.sys
HKLM\System\CurrentControlSet\Services\ratdrv.sys\ImagePath: C:\ratdrv.sys

Detected by UnHackMe:

RATDRV.SYS
Default location: C:\RATDRV.SYS

Dropper information:
MD5: 354a0b8d30a47fa22e9eb8dc67549c99
File size: 708096 bytes

Leave a Reply