BOVXDYYO.EXE – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

BOVXDYYO.EXE – Trojan Artemis removal

File MD5 Virus Alias
BOVXDYYO.EXE b55664cd1314cae5a3172a147c446a67 Trojan Artemis
BOVXDYYO.EXE b55664cd1314cae5a3172a147c446a67 Trojan FrauDrop
BOVXDYYO.EXE b55664cd1314cae5a3172a147c446a67 Trojan Downloader
BOVXDYYO.EXE b55664cd1314cae5a3172a147c446a67 Trojan CI
BOVXDYYO.EXE b55664cd1314cae5a3172a147c446a67 Trojan Crypt

BOVXDYYO.EXE size: 98304 bytes
BOVXDYYO.EXE hash: B55664CD1314CAE5A3172A147C446A67

Created files:

%Program Files%\Oracle\qAZwwtuo.exe
%Local AppData%\Microsoft\BovXdYyO.exe
%SysDir%\config\systemprofile\Start Menu\Programs\Startup\sdmmVYnN.exe
%TEMP%\nDakYmLtuh.exe
%TEMP%\OLCjeUbW.exe
%AppData%\Microsoft\Crypto\RSA\S-1-5-21-515967899-854245398-1708537768-1003\655a7350831c302c746f72e92c1ab924_78de4566-a5cc-4192-bf8d-014e0d2bd235

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: %WinDir%\System32\userinit.exe,,%Program Files%\Oracle\qAZwwtuo.exe
HKLM\System\CurrentControlSet\Services\wscsvc\Start: 04000000
HKLM\System\CurrentControlSet\Services\wuauserv\Start: 04000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\AkjsDDLS: %WinDir%\System32\config\Systemprofile\Local Settings\Application Data\Microsoft\BovXdYyO.exe

Detected by UnHackMe:

BOVXDYYO.EXE
Default location: %LOCAL APPDATA%\MICROSOFT\BOVXDYYO.EXE

Dropper information:
MD5: b55664cd1314cae5a3172a147c446a67
File size: 98304 bytes

Leave a Reply