I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
129BA5.SYS – Trojan Artemis removal
File | MD5 | Virus Alias |
---|---|---|
129BA5.SYS | dee846e5d867c6c72d489b44ef7d905b | Trojan Artemis |
129BA5.SYS | dee846e5d867c6c72d489b44ef7d905b | Trojan SuspiciousFile |
129BA5.SYS | dee846e5d867c6c72d489b44ef7d905b | Trojan Generic |
129BA5.SYS | dee846e5d867c6c72d489b44ef7d905b | Trojan Downloader |
129BA5.SYS | dee846e5d867c6c72d489b44ef7d905b | Trojan ZBot |
129BA5.SYS size: 54528 bytes
129BA5.SYS hash: DEE846E5D867C6C72D489B44EF7D905B
Created files:
%SysDir%\drivers\129ba5.sys
%Temp%\Huxim\momui.exe
Autostart registry keys:
HKLM\System\CurrentControlSet\Services\129ba5\Type: 01000000
HKLM\System\CurrentControlSet\Services\129ba5\Start: 01000000
HKLM\System\CurrentControlSet\Services\129ba5\DisplayName: momui.exe
HKLM\System\CurrentControlSet\Services\129ba5\ImagePath: %WinDir%\System32\drivers\129ba5.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Momui: “%Temp%\Huxim\momui.exe”
Detected by UnHackMe:
129BA5.SYS
Default location: %SYSDIR%\DRIVERS\129BA5.SYS
Dropper information:
MD5: 3d8277eae29afe5fa91180fc938f4b3c
File size: 776704 bytes