MEMBROS.EXE – Trojan Banker

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

MEMBROS.EXE – Trojan Banker removal

File MD5 Virus Alias
MEMBROS.EXE 977a1d810d5620b8f81db795f391f49d Trojan Banker
MEMBROS.EXE 977a1d810d5620b8f81db795f391f49d Trojan SuspiciousFile

MEMBROS.EXE size: 19211776 bytes
MEMBROS.EXE hash: 977A1D810D5620B8F81DB795F391F49D

Created files:

C:\Temp\AdC.dll
C:\Temp\AdCpI.dll
C:\Temp\AdM.Dll
C:\Temp\AdMpI.Dll
C:\Temp\AdTM.Dll
C:\Temp\AdTMpI.Dll
C:\Temp\aliases.conf
C:\Temp\AMsE.Dll
C:\Temp\AMsEpI.Dll
C:\Temp\APRE.dll
C:\Temp\Atualizador_New.exe
C:\Temp\BA.dll
C:\Temp\CapPluginFingercap.dll
C:\Temp\CartM.Dll
C:\Temp\CartR.Dll
C:\Temp\CartT.Dll
C:\Temp\CERT.Dll
C:\Temp\Config.exe
C:\Temp\cxRecibo.Dll
C:\Temp\DEBD.Dll
C:\Temp\ECM.Dll
C:\Temp\EdM.dll
C:\Temp\ET_CT.dll
C:\Temp\ET_IG.Dll
C:\Temp\EZTW32.DLL
C:\Temp\fbclient.dll
C:\Temp\fbguard.exe
C:\Temp\fbintl.conf
C:\Temp\fbintl.dll
C:\Temp\fbserver.exe
C:\Temp\fbudf.dll
C:\Temp\fb_lock_print.exe
C:\Temp\FdM.Dll
C:\Temp\firebird.conf
C:\Temp\firebird.msg
C:\Temp\Firebird2Control.cpl
C:\Temp\gbak.exe
C:\Temp\gdef.exe
C:\Temp\GDS32.DLL
C:\Temp\gfix.exe
C:\Temp\gpre.exe
C:\Temp\GrFinger.dll
C:\Temp\GrFingerX.dll
C:\Temp\gsec.exe
C:\Temp\gsplit.exe
C:\Temp\gstat.exe
C:\Temp\ib_udf.dll
C:\Temp\ib_util.dll
C:\Temp\icudt30.dll
C:\Temp\icuin30.dll
C:\Temp\icuuc30.dll
C:\Temp\Instalador.exe
C:\Temp\instclient.exe
C:\Temp\instreg.exe
C:\Temp\instsvc.exe
C:\Temp\Integrador.dll
C:\Temp\isql.exe
C:\Temp\LDC.dll
C:\Temp\LP.dll
C:\Temp\LPpI.dll
C:\Temp\LPR.dll
C:\Temp\LPRpI.dll
C:\Temp\LSM.Dll
C:\Temp\LSMpI.Dll
C:\Temp\Manutencao.exe
C:\Temp\MCM.Dll
C:\Temp\Membros.exe
C:\Temp\Membros.gdb
C:\Temp\midas.dll
C:\Temp\MIR.Dll
C:\Temp\Monitor.exe
C:\Temp\msvcp71.dll
C:\Temp\msvcr71.dll
C:\Temp\msvcrt.dll
C:\Temp\nbackup.exe
C:\Temp\pthreadVC2.dll
C:\Temp\qli.exe
C:\Temp\RA.dll
C:\Temp\RAdD.dll
C:\Temp\RAdI.dll
C:\Temp\RAdPS.dll
C:\Temp\RAdPSpIG.dll
C:\Temp\RAE.Dll
C:\Temp\RAF.Dll
C:\Temp\RAG.Dll
C:\Temp\RAGpDT.Dll
C:\Temp\RAMEBD.dll
C:\Temp\RAO.Dll
C:\Temp\RAR.Dll
C:\Temp\RARIF.dll
C:\Temp\RAT.Dll
C:\Temp\RBA.dll
C:\Temp\RBS.dll
C:\Temp\RCC.dll
C:\Temp\RCCE.dll
C:\Temp\RCEB.Dll
C:\Temp\RCEL.Dll
C:\Temp\RCGF.dll
C:\Temp\RCI.dll
C:\Temp\RCL.Dll
C:\Temp\RCLC.Dll
C:\Temp\RCPI.dll
C:\Temp\RCT.Dll
C:\Temp\RDC.dll
C:\Temp\RDdC.Dll
C:\Temp\RDE.Dll
C:\Temp\RDF.Dll
C:\Temp\RdFA.dll
C:\Temp\RDMA.Dll
C:\Temp\RDMP.Dll
C:\Temp\RDP.Dll
C:\Temp\RDRPC.Dll
C:\Temp\RDS.Dll
C:\Temp\RDT.Dll
C:\Temp\REC.Dll
C:\Temp\RECC.dll
C:\Temp\RECG.Dll
C:\Temp\RECpS.dll
C:\Temp\RECpSa.dll
C:\Temp\REdC.dll
C:\Temp\RelPosAnuidade.dll
C:\Temp\Remail.dll
C:\Temp\Remailpi.dll
C:\Temp\Remover.exe
C:\Temp\rFA.dll
C:\Temp\RFDC.dll
C:\Temp\RFU.Dll
C:\Temp\RGAO.dll
C:\Temp\RGDRD.dll
C:\Temp\RGEC.dll
C:\Temp\RGP.Dll
C:\Temp\RGRUS.dll
C:\Temp\RHQ.Dll
C:\Temp\RIFP.dll
C:\Temp\RIG.Dll
C:\Temp\RIG_SUP.Dll
C:\Temp\RIO.dll
C:\Temp\RIP.Dll
C:\Temp\RLCE.dll
C:\Temp\RLGF.dll
C:\Temp\RMF.dll
C:\Temp\RMI.Dll
C:\Temp\RMOL.dll
C:\Temp\RMP.dll
C:\Temp\RMPE.dll
C:\Temp\RMPS.dll
C:\Temp\RNA.Dll
C:\Temp\ROAO.dll
C:\Temp\ROAP.dll
C:\Temp\ROC.Dll
C:\Temp\ROCP.Dll
C:\Temp\ROPIAO.dll
C:\Temp\ROPIAP.dll
C:\Temp\RPA5.Dll
C:\Temp\RPB.Dll
C:\Temp\RPC.Dll
C:\Temp\RPCE.dll
C:\Temp\RPEB.Dll
C:\Temp\RPF.dll
C:\Temp\RPFC.dll
C:\Temp\RPFPF.dll
C:\Temp\RPFPIF.dll
C:\Temp\RPFPIP.dll
C:\Temp\RPGF.dll
C:\Temp\RPRA.dll
C:\Temp\RQPpI.Dll
C:\Temp\RRA.Dll
C:\Temp\RRD.Dll
C:\Temp\RRF.Dll
C:\Temp\RRFC.dll
C:\Temp\RRG.Dll
C:\Temp\RRI.Dll
C:\Temp\RRS.Dll
C:\Temp\RRTAC.Dll
C:\Temp\RSCE.dll
C:\Temp\RSEPE.dll
C:\Temp\RSGF.dll
C:\Temp\RTAC
C:\Temp\RTAC.Dll
C:\Temp\RTACA.Dll
C:\Temp\RTG.dll
C:\Temp\RTM.dll
C:\Temp\RTMpi.dll
C:\Temp\RTRF.Dll
C:\Temp\security2.fdb
C:\Temp\Set3050.exe
C:\Temp\ShowMyPC3010.exe
C:\Temp\tbudf.dll
C:\Temp\UpDateDataBase.dll
C:\Temp\Updatedatabase5.dll
C:\Temp\Updatedatabase6.dll
C:\Temp\Updatedatabase7.dll
C:\Temp\Updatedatabase8.dll

Detected by UnHackMe:

MEMBROS.EXE
Default location: C:\TEMP\MEMBROS.EXE

Dropper information:
MD5: 0c4db586e047fd32d7f99a1e370e430c
File size: 20641120 bytes

Leave a Reply