WARNING.EXE – Trojan Banload

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

WARNING.EXE – Trojan Banload removal

File MD5 Virus Alias
WARNING.EXE 2195b672577160bf9b286990a019b17a Trojan Banload
WARNING.EXE 2195b672577160bf9b286990a019b17a Trojan Downloader

WARNING.EXE size: 639488 bytes
WARNING.EXE hash: 2195B672577160BF9B286990A019B17A

Created files:

%AppData%\SisPlugin\MODBR.EXE
%AppData%\SisPlugin\MODIT.EXE
%AppData%\SisPlugin\Registry.passport
%AppData%\SisPlugin\START.EXE
%AppData%\SisPlugin\WARNING.EXE

Autostart registry keys:

HKCU\Software\Microsoft\Windows\CurrentVersion\RUN\MicrosoftPlugin: %WinDir%\System32\config\Systemprofile\Application Data\SisPlugin\Start.exe

Detected by UnHackMe:

WARNING.EXE
Default location: %APPDATA%\SISPLUGIN\WARNING.EXE

Dropper information:
MD5: 171c5c649bb25a641c2d1a492eeca587
File size: 2555392 bytes

Leave a Reply