Solved! Use GSAFE.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

GSAFE.EXE – Trojan Artemis removal

File MD5 Virus Alias
GSAFE.EXE 671d1acac8fe44f4b1f0a7a5f164f2c7 Trojan Artemis
GSAFE.EXE 671d1acac8fe44f4b1f0a7a5f164f2c7 Trojan SuspiciousFile
GSAFE.EXE 671d1acac8fe44f4b1f0a7a5f164f2c7 Trojan Generic
GSAFE.EXE 671d1acac8fe44f4b1f0a7a5f164f2c7 Trojan Agent

GSAFE.EXE size: 444416 bytes
GSAFE.EXE hash: 671D1ACAC8FE44F4B1F0A7A5F164F2C7

Created files:

%Program Files%\GSafe\GSafe.exe
%Program Files%\GSafe\libeay32.dll
%Program Files%\GSafe\nfapi.dll
%Program Files%\GSafe\ProtocolFilters.dll
%Program Files%\GSafe\ssleay32.dll
%Temp%\GSafe\SSL\gsafessl.cer
%Temp%\GSafe\SSL\import_root_cert.exe
%Temp%\GSafe\SSL\nss\certutil.exe
%Temp%\GSafe\SSL\nss\mozcrt19.dll
%Temp%\GSafe\SSL\nss\nspr4.dll
%Temp%\GSafe\SSL\nss\nss3.dll
%Temp%\GSafe\SSL\nss\plc4.dll
%Temp%\GSafe\SSL\nss\plds4.dll
%Temp%\GSafe\SSL\nss\smime3.dll
%Temp%\GSafe\SSL\nss\softokn3.dll
%Temp%\gsafe_aff_gw9.exe
%Temp%\utsd14.exe

Detected by UnHackMe:

GSAFE.EXE
Default location: %PROGRAM FILES%\GSAFE\GSAFE.EXE

Dropper information:
MD5: f2289bbdb8f6ac3bdf07cb07fadb9b28
File size: 2078249 bytes

Leave a Reply