Solved! Use MSTSC.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

MSTSC.EXE – Trojan Artemis removal

File MD5 Virus Alias
MSTSC.EXE 40d9cb955e5f7f6776626510928f6394 Trojan Artemis
MSTSC.EXE 40d9cb955e5f7f6776626510928f6394 Trojan SuspiciousFile
MSTSC.EXE 40d9cb955e5f7f6776626510928f6394 Trojan XPACK
MSTSC.EXE 40d9cb955e5f7f6776626510928f6394 Trojan Generic
MSTSC.EXE 40d9cb955e5f7f6776626510928f6394 Trojan ZBot
MSTSC.EXE 40d9cb955e5f7f6776626510928f6394 Trojan Crypt

MSTSC.EXE size: 1483776 bytes
MSTSC.EXE hash: 40D9CB955E5F7F6776626510928F6394

Created files:

%AppData%\Microsoft\mstsc.exe

Autostart registry keys:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Facebook Update: 2500410050005000440041005400410025005C004D006900630072006F0073006F00660074005C006D0073007400730063002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Facebook Update: 2500410050005000440041005400410025005C004D006900630072006F0073006F00660074005C006D0073007400730063002E006500780065000000
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: %APPDATA%\Microsoft\mstsc.exe,explorer.exe

Detected by UnHackMe:

MSTSC.EXE
Default location: %APPDATA%\MICROSOFT\MSTSC.EXE

Dropper information:
MD5: 40d9cb955e5f7f6776626510928f6394
File size: 1483776 bytes

Leave a Reply