I'm seeing the same four files repeat in the Temp Files / Shortcuts section of a Registry Mechanic scan.
\C:\ProgramData\McAfee\VirusScan\Data\TFRBBC1.tmp
\C:\ProgramData\Microsoft\Search\Data\Application\Windows\MCC.chk
\C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp
\C:\Users\Kevin\AppData\Local\Microsoft\Windows Mail\edb.chk
I'm also seeing the following two files in the Deep Scan section.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\7971f918-a847-4430-9279-4a52d1efe18d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\9482fb4-e343-43b6-b170-9a65bc822c77
Recent history: Less than a week ago, during a routine McAfee antivirus scan I discovered a half dozen files associated with the Artemis trojan. Several months earlier I found and debugged (also with McAfee) a different trojan. And the laptop has been slow for several weeks/months.
In anticipation of getting help here I tried running RootRepeal. That ran for more than 24 hours. So I stopped it. Then I tried running SysProt AntiRootkit. But McAfee wouldn't accept it and returned the following message.
McAfee has automatically blocked and removed a Trojan.
About this Trojan
Detected: Artemis!9CE216C69E21 (Trojan), Artemis!9CE216C69E21 (Trojan)
In general the laptop runs slow. And I suspect it's infected. Any help will be greatly appreciated. Thanks. What should I do first?
Regards,
Kevin
\C:\ProgramData\McAfee\VirusScan\Data\TFRBBC1.tmp
\C:\ProgramData\Microsoft\Search\Data\Application\Windows\MCC.chk
\C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp
\C:\Users\Kevin\AppData\Local\Microsoft\Windows Mail\edb.chk
I'm also seeing the following two files in the Deep Scan section.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\7971f918-a847-4430-9279-4a52d1efe18d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\9482fb4-e343-43b6-b170-9a65bc822c77
Recent history: Less than a week ago, during a routine McAfee antivirus scan I discovered a half dozen files associated with the Artemis trojan. Several months earlier I found and debugged (also with McAfee) a different trojan. And the laptop has been slow for several weeks/months.
In anticipation of getting help here I tried running RootRepeal. That ran for more than 24 hours. So I stopped it. Then I tried running SysProt AntiRootkit. But McAfee wouldn't accept it and returned the following message.
McAfee has automatically blocked and removed a Trojan.
About this Trojan
Detected: Artemis!9CE216C69E21 (Trojan), Artemis!9CE216C69E21 (Trojan)
In general the laptop runs slow. And I suspect it's infected. Any help will be greatly appreciated. Thanks. What should I do first?
Regards,
Kevin

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Back to top
> Run..., then copy and paste this command into the open box: cmd









