SYDNPYIFT.EXE – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SYDNPYIFT.EXE – Trojan Artemis removal

FileMD5Virus Alias
SYDNPYIFT.EXE b8e085c4511e6615ba5ae84801e633cc Trojan Artemis
SYDNPYIFT.EXE b8e085c4511e6615ba5ae84801e633cc Trojan SuspiciousFile
SYDNPYIFT.EXE b8e085c4511e6615ba5ae84801e633cc Trojan Generic
SYDNPYIFT.EXE b8e085c4511e6615ba5ae84801e633cc Trojan Downloader

SYDNPYIFT.EXE size: 211460 bytes
SYDNPYIFT.EXE hash: B8E085C4511E6615BA5AE84801E633CC

Created files:

%SysDir%\drivers\Xuchangad.sys
%TEMP%\njGceADAbH.exe
%TEMP%\SYdnPYiFT.exe
%TEMP%\Xuchangad.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Xuchangad\Type: 01000000
HKLM\System\CurrentControlSet\Services\Xuchangad\Start: 02000000
HKLM\System\CurrentControlSet\Services\Xuchangad\DisplayName: Xuchangad
HKLM\System\CurrentControlSet\Services\Xuchangad\ImagePath: %WinDir%\System32\drivers\Xuchangad.sys

Detected by UnHackMe:

SYDNPYIFT.EXE
Default location: %TEMP%\SYDNPYIFT.EXE

Dropper information:
MD5: 24a64a6920699696861189affda3f5c2
File size: 556328 bytes

Leave a Reply