Solved! Use MADED32.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

MADED32.EXE – Trojan Artemis removal

FileMD5Virus Alias
MADED32.EXE 2021403d9b19953d307be14bbb6be65d Trojan Artemis
MADED32.EXE 2021403d9b19953d307be14bbb6be65d Trojan Generic
MADED32.EXE 2021403d9b19953d307be14bbb6be65d Rootkit TDSS
MADED32.EXE 2021403d9b19953d307be14bbb6be65d Trojan Agent

MADED32.EXE size: 45116 bytes
MADED32.EXE hash: 2021403D9B19953D307BE14BBB6BE65D

Created files:

%Program Files%\Microsoft Ecaqwc\MADED32.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Wsqqmo myugkmdfme\ConnectGroup: ??????
HKLM\System\CurrentControlSet\Services\Wsqqmo myugkmdfme\MarkTime: 2014-11-18 03:50
HKLM\System\CurrentControlSet\Services\Wsqqmo myugkmdfme\Type: 10010000
HKLM\System\CurrentControlSet\Services\Wsqqmo myugkmdfme\Start: 02000000
HKLM\System\CurrentControlSet\Services\Wsqqmo myugkmdfme\DisplayName: Mnmsrp bgawmhhfgbj
HKLM\System\CurrentControlSet\Services\Wsqqmo myugkmdfme\ImagePath: %Program Files%\Microsoft Ecaqwc\MADED32.exe

Detected by UnHackMe:

MADED32.EXE
Default location: %PROGRAM FILES%\MICROSOFT ECAQWC\MADED32.EXE

Dropper information:
MD5: 2021403d9b19953d307be14bbb6be65d
File size: 45116 bytes

Leave a Reply