OFFICEUPDATE.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

OFFICEUPDATE.EXE – Trojan Delf removal

FileMD5Virus Alias
OFFICEUPDATE.EXE 4b3e95e9d0870804c37f4fc6da0f05c0 Trojan Delf
OFFICEUPDATE.EXE 4b3e95e9d0870804c37f4fc6da0f05c0 Trojan Generic
OFFICEUPDATE.EXE 4b3e95e9d0870804c37f4fc6da0f05c0 Trojan Hllw

OFFICEUPDATE.EXE size: 139264 bytes
OFFICEUPDATE.EXE hash: 4B3E95E9D0870804C37F4FC6DA0F05C0

Created files:

C:\autoply.exe
%Program Files Common%\Microsoft Shared\MSshare.exe
%Program Files%\Sound Utility\Soundmax.exe
%TEMP%\svchost.exe
%WinDir%\Web\OfficeUpdate.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SoundMax: %Program Files%\Sound Utility\Soundmax.exe

Detected by UnHackMe:

OFFICEUPDATE.EXE
Default location: %WinDir%\WEB\OFFICEUPDATE.EXE

Dropper information:
MD5: 4b3e95e9d0870804c37f4fc6da0f05c0
File size: 139264 bytes

Leave a Reply