NTSVCHOST.EXE – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

NTSVCHOST.EXE – Trojan Artemis removal

FileMD5Virus Alias
NTSVCHOST.EXE bffb798f1f95101e9ba7d28f01625d8f Trojan Artemis
NTSVCHOST.EXE bffb798f1f95101e9ba7d28f01625d8f Trojan SuspiciousFile
NTSVCHOST.EXE bffb798f1f95101e9ba7d28f01625d8f Trojan Generic
NTSVCHOST.EXE bffb798f1f95101e9ba7d28f01625d8f Trojan Graftor
NTSVCHOST.EXE bffb798f1f95101e9ba7d28f01625d8f Trojan Agent
NTSVCHOST.EXE bffb798f1f95101e9ba7d28f01625d8f Trojan ZBot

NTSVCHOST.EXE size: 157184 bytes
NTSVCHOST.EXE hash: BFFB798F1F95101E9BA7D28F01625D8F

Created files:

%SysDir%\34787.bi
%SysDir%\ntsvchost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\ProxyService\Type: 10000000
HKLM\System\CurrentControlSet\Services\ProxyService\Start: 02000000
HKLM\System\CurrentControlSet\Services\ProxyService\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\ProxyService\ImagePath: “%WinDir%\System32\ntsvchost.exe” service

Detected by UnHackMe:

NTSVCHOST.EXE
Default location: %SYSDIR%\NTSVCHOST.EXE

Dropper information:
MD5: bffb798f1f95101e9ba7d28f01625d8f
File size: 157184 bytes

Leave a Reply