I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
Trojan Banker
Also known as: KeyLogger Ardamax, Trojan Bancos
SHA256: 01e11cf9ff0659db6ef67082291f4e78c71a31d8a21df5da271f7d7d32b3cd01
SHA1: 706ca7d0730105be443c465ef073ced25db451db
MD5: 9dc0cdc9a8bbdbe13da3a39c1fee1a32
File size: 846991 bytes
Created files:
C:\windows\system32\Exlorer.EXE – Trojan Banker
C:\windows\system32\iexlorer.exe – Trojan Banker
Trojan Banker created autostart registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Exlorer: C:\windows\System32\Exlorer.EXE
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe C:\windows\System32\Exlorer.EXE