Solved! Use VCVRYI.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

VCVRYI.EXE – Trojan Artemis removal

File MD5 Virus Alias
VCVRYI.EXE 8b304602391f3769b2f110342d7d6454 Trojan Artemis
VCVRYI.EXE 8b304602391f3769b2f110342d7d6454 Trojan DLOADER
VCVRYI.EXE 8b304602391f3769b2f110342d7d6454 Trojan SuspiciousFile
VCVRYI.EXE 8b304602391f3769b2f110342d7d6454 Trojan Generic
VCVRYI.EXE 8b304602391f3769b2f110342d7d6454 Trojan CI
VCVRYI.EXE 8b304602391f3769b2f110342d7d6454 Trojan Graftor

VCVRYI.EXE size: 12693624 bytes
VCVRYI.EXE hash: 8B304602391F3769B2F110342D7D6454

Created files:

%SysDir%\vcvryi.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\BITS\InitTime: 20150124
HKLM\System\CurrentControlSet\Services\BITS\Version: hsrOzPw=
HKLM\System\CurrentControlSet\Services\BITS\Group: uJmWnYmQiPw=
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Type: 10010000
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Start: 02000000
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\DisplayName: Jklmno Qrstuvwx Abcdefgh Jklm
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\ImagePath: %WinDir%\System32\vcvryi.exe
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Description: Jklmnopq Stuvwxyab Defghij Lmnopqrs Uvw

Detected by UnHackMe:

VCVRYI.EXE
Default location: %SYSDIR%\VCVRYI.EXE

Dropper information:
MD5: ccf2a36a5caaeb5ca4f2504073aa578a
File size: 110712 bytes

Leave a Reply