Solved! Use BUILDER.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

BUILDER.EXE – Trojan Artemis removal

File MD5 Virus Alias
BUILDER.EXE 614cd1414c7b7d48972dfa8cedb1def0 Trojan Artemis
BUILDER.EXE 614cd1414c7b7d48972dfa8cedb1def0 Trojan, Suspicious File
BUILDER.EXE 614cd1414c7b7d48972dfa8cedb1def0 Trojan Win32-Spy
BUILDER.EXE 614cd1414c7b7d48972dfa8cedb1def0 Trojan Generic
BUILDER.EXE 614cd1414c7b7d48972dfa8cedb1def0 Trojan MulDrop4
BUILDER.EXE 614cd1414c7b7d48972dfa8cedb1def0 Trojan CI

BUILDER.EXE size: 632320 bytes
BUILDER.EXE hash: 614CD1414C7B7D48972DFA8CEDB1DEF0

Created files:

%Program Files%\SuperSoft\Builder.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{14454TUL-SA36-M3J0-L21Y-IELME3B7X433}\StubPath: %Program Files%\SuperSoft\Builder.exe Restart
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Builder: 43003A005C00500072006F006700720061006D002000460069006C00650073005C005300750070006500720053006F00660074005C004200750069006C006400650072002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Builder: 43003A005C00500072006F006700720061006D002000460069006C00650073005C005300750070006500720053006F00660074005C004200750069006C006400650072002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Builder: 43003A005C00500072006F006700720061006D002000460069006C00650073005C005300750070006500720053006F00660074005C004200750069006C006400650072002E006500780065000000

Detected by UnHackMe:

BUILDER.EXE
Default location: %PROGRAM FILES%\SUPERSOFT\BUILDER.EXE

Dropper information:
MD5: 614cd1414c7b7d48972dfa8cedb1def0
File size: 632320 bytes

Leave a Reply