WIN[SYSTEM PROCESS].EXE – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

WIN[SYSTEM PROCESS].EXE – Trojan Artemis removal

FileMD5Virus Alias
WIN[SYSTEM PROCESS].EXE 401c409489d99ab5ff4d5bede51236d3 Trojan Artemis
WIN[SYSTEM PROCESS].EXE 401c409489d99ab5ff4d5bede51236d3 Trojan Generic
WIN[SYSTEM PROCESS].EXE 401c409489d99ab5ff4d5bede51236d3 Trojan Agent

WIN[SYSTEM PROCESS].EXE size: 81598 bytes
WIN[SYSTEM PROCESS].EXE hash: 401C409489D99AB5FF4D5BEDE51236D3

Created files:

%SysDir%\34787.bi
%SysDir%\win[system process].exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\ProxyService\Type: 10000000
HKLM\System\CurrentControlSet\Services\ProxyService\Start: 02000000
HKLM\System\CurrentControlSet\Services\ProxyService\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\ProxyService\ImagePath: “%WinDir%\System32\win[System process].exe” service

Detected by UnHackMe:

WIN[SYSTEM PROCESS].EXE
Default location: %SYSDIR%\WIN[SYSTEM PROCESS].EXE

Dropper information:
MD5: 401c409489d99ab5ff4d5bede51236d3
File size: 81598 bytes

Leave a Reply