HHA.DLL – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

HHA.DLL – Trojan Artemis removal

FileMD5Virus Alias
HHA.DLL f891656928bc08ea2e30f587c4b29963 Trojan Artemis
HHA.DLL f891656928bc08ea2e30f587c4b29963 Trojan CI
HHA.DLL f891656928bc08ea2e30f587c4b29963 Backdoor Plugx
HHA.DLL f891656928bc08ea2e30f587c4b29963 Trojan Small

HHA.DLL size: 40960 bytes
HHA.DLL hash: F891656928BC08EA2E30F587C4B29963

Created files:

%WinDir%\Temp\1.docx
%WinDir%\Temp\1.exe
%WinDir%\Temp\hhx\hha.dll
%WinDir%\Temp\hhx\hha.dll.bak
%WinDir%\Temp\hhx\hhc.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Credential Manager Command Line Utility\Type: 10010000
HKLM\System\CurrentControlSet\Services\Credential Manager Command Line Utility\Start: 02000000
HKLM\System\CurrentControlSet\Services\Credential Manager Command Line Utility\DisplayName: Credential Manager Command Line Utility
HKLM\System\CurrentControlSet\Services\Credential Manager Command Line Utility\ImagePath: “%WinDir%\Temp\hhx\hhc.exe” 200 0

Detected by UnHackMe:

HHA.DLL
Default location: %TEMP%\HHX\HHA.DLL

Dropper information:
MD5: 003b2d27d210082d08c3f3e5a26f56e6
File size: 288758 bytes

Leave a Reply