Solved! Use IYYESMS.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

IYYESMS.EXE – Trojan Artemis removal

FileMD5Virus Alias
IYYESMS.EXE b38a7e8484d180aea49b7ab1a3783512 Trojan Artemis
IYYESMS.EXE b38a7e8484d180aea49b7ab1a3783512 Trojan SuspiciousFile
IYYESMS.EXE b38a7e8484d180aea49b7ab1a3783512 Trojan Agent
IYYESMS.EXE b38a7e8484d180aea49b7ab1a3783512 Trojan FakeAV

IYYESMS.EXE size: 53248 bytes
IYYESMS.EXE hash: B38A7E8484D180AEA49B7AB1A3783512

Created files:

%Program Files%\Windows NT\Iyyesms.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Wsqqwk wwqcqsem\ConnectGroup: 3306.8.10
HKLM\System\CurrentControlSet\Services\Wsqqwk wwqcqsem\MarkTime: 2014-10-08 08:04
HKLM\System\CurrentControlSet\Services\Wsqqwk wwqcqsem\Type: 10010000
HKLM\System\CurrentControlSet\Services\Wsqqwk wwqcqsem\Start: 02000000
HKLM\System\CurrentControlSet\Services\Wsqqwk wwqcqsem\DisplayName: Qaqmou moaecsky
HKLM\System\CurrentControlSet\Services\Wsqqwk wwqcqsem\ImagePath: %Program Files%\Windows NT\Iyyesms.exe

Detected by UnHackMe:

IYYESMS.EXE
Default location: %PROGRAM FILES%\WINDOWS NT\IYYESMS.EXE

Dropper information:
MD5: b38a7e8484d180aea49b7ab1a3783512
File size: 53248 bytes

Leave a Reply