NJGCEADABH.EXE – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

NJGCEADABH.EXE – Trojan Artemis removal

FileMD5Virus Alias
NJGCEADABH.EXE 24a64a6920699696861189affda3f5c2 Trojan Artemis
NJGCEADABH.EXE 24a64a6920699696861189affda3f5c2 Trojan SuspiciousFile
NJGCEADABH.EXE 24a64a6920699696861189affda3f5c2 Trojan Agent

NJGCEADABH.EXE size: 556328 bytes
NJGCEADABH.EXE hash: 24A64A6920699696861189AFFDA3F5C2

Created files:

%SysDir%\drivers\Xuchangad.sys
%TEMP%\njGceADAbH.exe
%TEMP%\SYdnPYiFT.exe
%TEMP%\Xuchangad.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Xuchangad\Type: 01000000
HKLM\System\CurrentControlSet\Services\Xuchangad\Start: 02000000
HKLM\System\CurrentControlSet\Services\Xuchangad\DisplayName: Xuchangad
HKLM\System\CurrentControlSet\Services\Xuchangad\ImagePath: %WinDir%\System32\drivers\Xuchangad.sys

Detected by UnHackMe:

NJGCEADABH.EXE
Default location: %TEMP%\NJGCEADABH.EXE

Dropper information:
MD5: 24a64a6920699696861189affda3f5c2
File size: 556328 bytes

Leave a Reply