CARDCTRL.EXE – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CARDCTRL.EXE – Trojan Artemis removal

FileMD5Virus Alias
CARDCTRL.EXE 035627263fac59f11125b93d0e5d6279 Trojan Artemis
CARDCTRL.EXE 035627263fac59f11125b93d0e5d6279 Trojan PAK_Generic
CARDCTRL.EXE 035627263fac59f11125b93d0e5d6279 Trojan Generic
CARDCTRL.EXE 035627263fac59f11125b93d0e5d6279 Trojan Eldorado
CARDCTRL.EXE 035627263fac59f11125b93d0e5d6279 Trojan Downloader
CARDCTRL.EXE 035627263fac59f11125b93d0e5d6279 Trojan Agent

CARDCTRL.EXE size: 78336 bytes
CARDCTRL.EXE hash: 035627263FAC59F11125B93D0E5D6279

Created files:

%SysDir%\cardctrl.exe
%SysDir%\drivers\usbinckey.sys
%SysDir%\usbinckey.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\cardctrl\Type: 10000000
HKLM\System\CurrentControlSet\Services\cardctrl\Start: 02000000
HKLM\System\CurrentControlSet\Services\cardctrl\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\cardctrl\DisplayName: Windows Cards Manager
HKLM\System\CurrentControlSet\Services\cardctrl\ImagePath: %WinDir%\System32\cardctrl.exe
HKLM\System\CurrentControlSet\Services\usbinckey\Type: 01000000
HKLM\System\CurrentControlSet\Services\usbinckey\Start: 01000000
HKLM\System\CurrentControlSet\Services\usbinckey\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\usbinckey\DisplayName: usbinckey
HKLM\System\CurrentControlSet\Services\usbinckey\ImagePath: System32\drivers\usbinckey.sys

Detected by UnHackMe:

CARDCTRL.EXE
Default location: %SYSDIR%\CARDCTRL.EXE

Dropper information:
MD5: 035627263fac59f11125b93d0e5d6279
File size: 78336 bytes

Leave a Reply