WINSEARCHCP.DLL – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

WINSEARCHCP.DLL – Trojan Artemis removal

FileMD5Virus Alias
WINSEARCHCP.DLL abd2e3630baeba25d8fb32f111f33ad1 Trojan Artemis
WINSEARCHCP.DLL abd2e3630baeba25d8fb32f111f33ad1 Trojan Generic
WINSEARCHCP.DLL abd2e3630baeba25d8fb32f111f33ad1 Trojan CI
WINSEARCHCP.DLL abd2e3630baeba25d8fb32f111f33ad1 Adware Kraddare
WINSEARCHCP.DLL abd2e3630baeba25d8fb32f111f33ad1 Trojan ADH

WINSEARCHCP.DLL size: 122768 bytes
WINSEARCHCP.DLL hash: ABD2E3630BAEBA25D8FB32F111F33AD1

Created files:

%Program Files%\Winsearchcp\installwin.exe
%Program Files%\Winsearchcp\Uninstall.exe
%Program Files%\Winsearchcp\winsearchcp.dll
%Program Files%\Winsearchcp\winsearchcpdl.exe
%SysDir%\INETKO.DLL
%SysDir%\winsearchcpinst.exe

Autostart registry keys:

HKLM\Software\Classes\CLSID\{0E205AC2-FB09-4C7D-91F4-054CB3B93AE7}\InprocServer32 : %Program Files%\Winsearchcp\winsearchcp.dll
HKLM\Software\Classes\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59294-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59295-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX

Detected by UnHackMe:

WINSEARCHCP.DLL
Default location: %PROGRAM FILES%\WINSEARCHCP\WINSEARCHCP.DLL

Dropper information:
MD5: 5bfe9651bdc3b2e0201049402dea9bb2
File size: 901120 bytes

Leave a Reply