Solved! Use JSNHYAH.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

JSNHYAH.EXE – Trojan Artemis removal

File MD5 Virus Alias
JSNHYAH.EXE 3077a21557bb98cfacc121ea632accf0 Trojan Artemis
JSNHYAH.EXE 3077a21557bb98cfacc121ea632accf0 Trojan Generic
JSNHYAH.EXE 3077a21557bb98cfacc121ea632accf0 Trojan Banker

JSNHYAH.EXE size: 43808 bytes
JSNHYAH.EXE hash: 3077A21557BB98CFACC121EA632ACCF0

Created files:

C:\47qp437q127\Jsnhyah.exe
C:\tmp\Wiseman.exe

Autostart registry keys:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Wiseman: C:\tmp\Wiseman.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\EvtMgr: C:\47qp437q127\Jsnhyah.exe /Klaunchp

Detected by UnHackMe:

JSNHYAH.EXE
Default location: C:\47QP437Q127\JSNHYAH.EXE

Dropper information:
MD5: 26ecdfdae08d8154719e2e79031353df
File size: 264200 bytes

Leave a Reply