Solved! Use LJOXEZO.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

LJOXEZO.EXE – Trojan Artemis removal

FileMD5Virus Alias
LJOXEZO.EXE dede8beb272e70889ccabbcd68564ac9 Trojan Artemis
LJOXEZO.EXE dede8beb272e70889ccabbcd68564ac9 Trojan SuspiciousFile
LJOXEZO.EXE dede8beb272e70889ccabbcd68564ac9 Trojan Generic
LJOXEZO.EXE dede8beb272e70889ccabbcd68564ac9 Trojan Downloader
LJOXEZO.EXE dede8beb272e70889ccabbcd68564ac9 Trojan CI
LJOXEZO.EXE dede8beb272e70889ccabbcd68564ac9 Trojan Buzus

LJOXEZO.EXE size: 28672 bytes
LJOXEZO.EXE hash: DEDE8BEB272E70889CCABBCD68564AC9

Created files:

%Program Files%\AppPatch\NetSyst69.dll
%Program Files%\Microsoft Ccusog\Ljoxezo.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Wsumui qawmagmm\DeleteFiles: DEDE8BEB272E70889CCABBCD68564AC9.EXE
HKLM\System\CurrentControlSet\Services\Wsumui qawmagmm\ConnectGroup: ??????
HKLM\System\CurrentControlSet\Services\Wsumui qawmagmm\Type: 10010000
HKLM\System\CurrentControlSet\Services\Wsumui qawmagmm\Start: 02000000
HKLM\System\CurrentControlSet\Services\Wsumui qawmagmm\DisplayName: Segkck wcuoeqoseaewgisweg
HKLM\System\CurrentControlSet\Services\Wsumui qawmagmm\ImagePath: %Program Files%\Microsoft Ccusog\Ljoxezo.exe

Detected by UnHackMe:

LJOXEZO.EXE
Default location: %PROGRAM FILES%\MICROSOFT CCUSOG\LJOXEZO.EXE

Dropper information:
MD5: dede8beb272e70889ccabbcd68564ac9
File size: 28672 bytes

Leave a Reply