I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
49E4F7.SYS – Trojan Artemis removal
File | MD5 | Virus Alias |
---|---|---|
49E4F7.SYS | 05b5a9b1e4b68e5e3702021389383529 | Trojan Artemis |
49E4F7.SYS | 05b5a9b1e4b68e5e3702021389383529 | Trojan SuspiciousFile |
49E4F7.SYS | 05b5a9b1e4b68e5e3702021389383529 | Trojan Generic |
49E4F7.SYS | 05b5a9b1e4b68e5e3702021389383529 | Trojan Downloader |
49E4F7.SYS | 05b5a9b1e4b68e5e3702021389383529 | Trojan ZBot |
49E4F7.SYS size: 33024 bytes
49E4F7.SYS hash: 05B5A9B1E4B68E5E3702021389383529
Created files:
%SysDir%\drivers\49e4f7.sys
%Temp%\Jyluru\kaquce.exe
Autostart registry keys:
HKLM\System\CurrentControlSet\Services\49e4f7\Type: 01000000
HKLM\System\CurrentControlSet\Services\49e4f7\Start: 01000000
HKLM\System\CurrentControlSet\Services\49e4f7\DisplayName: kaquce.exe
HKLM\System\CurrentControlSet\Services\49e4f7\ImagePath: %WinDir%\System32\drivers\49e4f7.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Kaquce: “%Temp%\Jyluru\kaquce.exe”
Detected by UnHackMe:
49E4F7.SYS
Default location: %SYSDIR%\DRIVERS\49E4F7.SYS
Dropper information:
MD5: fedd7b7708f398717a56ef3d447f9cf9
File size: 455528 bytes