Solved! Use LATVZLF.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

LATVZLF.EXE – Trojan Artemis removal

FileMD5Virus Alias
LATVZLF.EXE 29f9691b71fe4132abfa9dfdbd5d376e Trojan Artemis
LATVZLF.EXE 29f9691b71fe4132abfa9dfdbd5d376e Trojan Generic
LATVZLF.EXE 29f9691b71fe4132abfa9dfdbd5d376e Trojan Downloader
LATVZLF.EXE 29f9691b71fe4132abfa9dfdbd5d376e Rootkit TDSS
LATVZLF.EXE 29f9691b71fe4132abfa9dfdbd5d376e Trojan Agent
LATVZLF.EXE 29f9691b71fe4132abfa9dfdbd5d376e Backdoor Farfli

LATVZLF.EXE size: 49152 bytes
LATVZLF.EXE hash: 29F9691B71FE4132ABFA9DFDBD5D376E

Created files:

%Program Files%\Microsoft Emeeam\Latvzlf.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Wskqqo qugogcqa\ConnectGroup: ??????
HKLM\System\CurrentControlSet\Services\Wskqqo qugogcqa\MarkTime: 2014-10-08 06:52
HKLM\System\CurrentControlSet\Services\Wskqqo qugogcqa\Type: 10010000
HKLM\System\CurrentControlSet\Services\Wskqqo qugogcqa\Start: 02000000
HKLM\System\CurrentControlSet\Services\Wskqqo qugogcqa\DisplayName: Uuiiyq aqiuqmaa
HKLM\System\CurrentControlSet\Services\Wskqqo qugogcqa\ImagePath: %Program Files%\Microsoft Emeeam\Latvzlf.exe

Detected by UnHackMe:

LATVZLF.EXE
Default location: %PROGRAM FILES%\MICROSOFT EMEEAM\LATVZLF.EXE

Dropper information:
MD5: 29f9691b71fe4132abfa9dfdbd5d376e
File size: 49152 bytes

Leave a Reply