YAHOO.EXE – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

YAHOO.EXE – Trojan Artemis removal

FileMD5Virus Alias
YAHOO.EXE 0283e332d72285fff8a1957c0d4ec453 Trojan Artemis
YAHOO.EXE 0283e332d72285fff8a1957c0d4ec453 Trojan XPACK
YAHOO.EXE 0283e332d72285fff8a1957c0d4ec453 Trojan Eldorado
YAHOO.EXE 0283e332d72285fff8a1957c0d4ec453 Trojan Siggen
YAHOO.EXE 0283e332d72285fff8a1957c0d4ec453 Trojan Agent
YAHOO.EXE 0283e332d72285fff8a1957c0d4ec453 Trojan Kryptik

YAHOO.EXE size: 33792 bytes
YAHOO.EXE hash: 0283E332D72285FFF8A1957C0D4EC453

Created files:

%SysDir%\win32\yahoo.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{8B7S1ON4-NI7K-6EL2-3IB1-E026J3B8GW2W}\StubPath: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C00770069006E00330032005C007900610068006F006F002E006500780065000000
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\HKLM: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C00770069006E00330032005C007900610068006F006F002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\HKCU: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C00770069006E00330032005C007900610068006F006F002E006500780065000000

Detected by UnHackMe:

YAHOO.EXE
Default location: %SYSDIR%\WIN32\YAHOO.EXE

Dropper information:
MD5: 0283e332d72285fff8a1957c0d4ec453
File size: 33792 bytes

Leave a Reply