Solved! Use WORKFILE.EXE (Trojan Banker) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

WORKFILE.EXE – Trojan Banker removal

File MD5 Virus Alias
WORKFILE.EXE bc3353d57772a6aaa3161a8f8f6cea61 Trojan Banker
WORKFILE.EXE bc3353d57772a6aaa3161a8f8f6cea61 Trojan Generic
WORKFILE.EXE bc3353d57772a6aaa3161a8f8f6cea61 Trojan Eldorado
WORKFILE.EXE bc3353d57772a6aaa3161a8f8f6cea61 Backdoor Pigeon
WORKFILE.EXE bc3353d57772a6aaa3161a8f8f6cea61 Trojan Bancos

WORKFILE.EXE size: 9024512 bytes
WORKFILE.EXE hash: BC3353D57772A6AAA3161A8F8F6CEA61

Created files:

%WinDir%\msn_1508.dll
%SysDir%\WorkFile.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WorkFile: %WinDir%\System32\WorkFile.exe

Detected by UnHackMe:

WORKFILE.EXE
Default location: %SYSDIR%\WORKFILE.EXE

Dropper information:
MD5: bc3353d57772a6aaa3161a8f8f6cea61
File size: 9024512 bytes

Leave a Reply