Trojan FakeAV – rti.exe – 5745f0d8502a613ab3dd37e71a130f81

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan FakeAV
Also known as: Trojan Generic.KD, Trojan Banker
SHA256: b23dc032331ca518dde8c3c3c721f757644508eaeea935b0bd8c3fa947d08cdb
SHA1: 91a7818777b31ea7d87cdfae5fae4bb3bee4c8bf
MD5: 5745f0d8502a613ab3dd37e71a130f81
File size: 327680 bytes

Created files:

%SysDir%\config\systemprofile\Local Settings\Application Data\rti.exe – Trojan FakeAV

Trojan FakeAV created autostart registry keys:

HKLM\System\CurrentControlSet\Services\SharedAccess\Start: 04000000
HKLM\System\CurrentControlSet\Services\wuauserv: deleted registry key

Leave a Reply