lsass32.exe – Trojan Banker

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

lsass32.exe – Trojan Banker removal

FileVirus Alias
lsass32.exe Trojan Banker
lsass32.exe Trojan Spy
lsass32.exe Trojan Bancos
lsass32.exe Trojan Generic
lsass32.exe Trojan Banload
lsass32.exe Trojan PWS

Created files:

%SysDir%\lsass32.exe – Trojan Banker
%AllUsersProfile%\start menu\programs\startup\lsass32.exe – Trojan Banker

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\lsass32: %WinDir%\System32\lsass32.exe

Detected by UnHackMe:

lsass32.exe
Default location: %SysDir%\lsass32.exe

Dropper information:
SHA256: 7e3fbd03448f3e089d49e32f4b433104ee2432e2d265db5eabdf74ef1510055f
SHA1: 5cc9bb4f1817cf6e15bd92e6606b52460b1065e8
MD5: 500ca119e420042f5f37c58eda7f35cc
File size: 730479 bytes

Leave a Reply