Solved! Use UPSYS.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

UPSYS.EXE – Trojan Artemis removal

File MD5 Virus Alias
UPSYS.EXE d926c89e35498d662f147acadf661e17 Trojan Artemis
UPSYS.EXE d926c89e35498d662f147acadf661e17 Trojan PAK_Generic

UPSYS.EXE size: 29696 bytes
UPSYS.EXE hash: D926C89E35498D662F147ACADF661E17

Created files:

C:\Documents and Settings\Administrator\Favorites\Fixed_Directory_Name\UnicodeFile.bin
C:\Documents and Settings\Administrator\Favorites\Fixed_Directory_Name\UnicodeFile_1.bin
C:\Documents and Settings\Administrator\Favorites\Fixed_Directory_Name\UnicodeFile_2.bin
C:\Documents and Settings\Administrator\Fixed_Directory_Name\UnicodeFile.bin
%WinDir%\arp+.exe
%WinDir%\DriverFire.exe
%WinDir%\FireDll.dll
%WinDir%\ie.exe
%WinDir%\run.vbs
%SYSDIR%\ie.exe
%SYSDIR%\IE_BHO.dll
%SYSDIR%\MainPro.exe
%WinDir%\UpSys.exe
%WinDir%\zm.exe

Detected by UnHackMe:

UPSYS.EXE
Default location: %WinDir%\UPSYS.EXE

Dropper information:
MD5: c5dad691ced225bcfc8af40fb42536a3
File size: 2311535 bytes

Leave a Reply