Solved! Use SYSTRAY.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SYSTRAY.EXE – Trojan Artemis removal

File MD5 Virus Alias
SYSTRAY.EXE efaa75acaeb5e7f39d41ba19fe3c8c40 Trojan Artemis
SYSTRAY.EXE efaa75acaeb5e7f39d41ba19fe3c8c40 Trojan, Suspicious File
SYSTRAY.EXE efaa75acaeb5e7f39d41ba19fe3c8c40 Trojan DNAScan
SYSTRAY.EXE efaa75acaeb5e7f39d41ba19fe3c8c40 Trojan Delphi
SYSTRAY.EXE efaa75acaeb5e7f39d41ba19fe3c8c40 Trojan Delf

SYSTRAY.EXE size: 15358 bytes
SYSTRAY.EXE hash: EFAA75ACAEB5E7F39D41BA19FE3C8C40

Created files:

%WinDir%\svchost.exe
%WinDir%\systray.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\svchost.exe: %WinDir%\svchost.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\svchost.exe: %WinDir%\svchost.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\svchost.exe: %WinDir%\svchost.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\svchost.exe: %WinDir%\svchost.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\systray.exe: %WinDir%\systray.exe

Detected by UnHackMe:

SYSTRAY.EXE
Default location: %WinDir%\SYSTRAY.EXE

Dropper information:
MD5: 0fd0ee1f377aac975e41b01bf8271100
File size: 15333 bytes

Leave a Reply