QAZWWTUO.EXE – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

QAZWWTUO.EXE – Trojan Artemis removal

FileMD5Virus Alias
QAZWWTUO.EXE 34dd59dd69c627d5b285e50542682f67 Trojan Artemis
QAZWWTUO.EXE 34dd59dd69c627d5b285e50542682f67 Trojan Ransom
QAZWWTUO.EXE 34dd59dd69c627d5b285e50542682f67 Trojan XPACK
QAZWWTUO.EXE 34dd59dd69c627d5b285e50542682f67 Trojan Generic
QAZWWTUO.EXE 34dd59dd69c627d5b285e50542682f67 Trojan Crypt

QAZWWTUO.EXE size: 197632 bytes
QAZWWTUO.EXE hash: 34DD59DD69C627D5B285E50542682F67

Created files:

%Program Files%\Oracle\qAZwwtuo.exe
%Local AppData%\Microsoft\BovXdYyO.exe
%SysDir%\config\systemprofile\Start Menu\Programs\Startup\sdmmVYnN.exe
%TEMP%\OLCjeUbW.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: %WinDir%\System32\userinit.exe,,%Program Files%\Oracle\qAZwwtuo.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\AkjsDDLS: %WinDir%\System32\config\Systemprofile\Local Settings\Application Data\Microsoft\BovXdYyO.exe

Detected by UnHackMe:

QAZWWTUO.EXE
Default location: %PROGRAM FILES%\ORACLE\QAZWWTUO.EXE

Dropper information:
MD5: 34dd59dd69c627d5b285e50542682f67
File size: 197632 bytes

Leave a Reply