WINDOWSUPDATE.EXE – Trojan Banker

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

WINDOWSUPDATE.EXE – Trojan Banker removal

File MD5 Virus Alias
WINDOWSUPDATE.EXE e8b7999c5c3d4d8255eb1603ac5db691 Trojan Banker
WINDOWSUPDATE.EXE e8b7999c5c3d4d8255eb1603ac5db691 Trojan SuspiciousFile
WINDOWSUPDATE.EXE e8b7999c5c3d4d8255eb1603ac5db691 Trojan Artemis
WINDOWSUPDATE.EXE e8b7999c5c3d4d8255eb1603ac5db691 Trojan Generic
WINDOWSUPDATE.EXE e8b7999c5c3d4d8255eb1603ac5db691 Trojan Downloader
WINDOWSUPDATE.EXE e8b7999c5c3d4d8255eb1603ac5db691 Trojan Delf

WINDOWSUPDATE.EXE size: 2199552 bytes
WINDOWSUPDATE.EXE hash: E8B7999C5C3D4D8255EB1603AC5DB691

Created files:

%TEMP%\CDELoop.tl
%TEMP%\SW4.exe
%TEMP%\WindowsUpdate.exe

Autostart registry keys:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ : %TEMP%\WindowsUpdate.exe

Detected by UnHackMe:

WINDOWSUPDATE.EXE
Default location: %TEMP%\WINDOWSUPDATE.EXE

Dropper information:
MD5: e8b7999c5c3d4d8255eb1603ac5db691
File size: 2199552 bytes

Leave a Reply