UPDATE18.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

UPDATE18.EXE – Trojan Delf removal

FileMD5Virus Alias
UPDATE18.EXE 742189a79e7f2d55c0a8322e8d55d72c Trojan Delf
UPDATE18.EXE 742189a79e7f2d55c0a8322e8d55d72c Trojan Artemis
UPDATE18.EXE 742189a79e7f2d55c0a8322e8d55d72c Trojan Generic
UPDATE18.EXE 742189a79e7f2d55c0a8322e8d55d72c Trojan Eldorado
UPDATE18.EXE 742189a79e7f2d55c0a8322e8d55d72c Trojan Downloader
UPDATE18.EXE 742189a79e7f2d55c0a8322e8d55d72c Trojan Agent

UPDATE18.EXE size: 194560 bytes
UPDATE18.EXE hash: 742189A79E7F2D55C0A8322E8D55D72C

Created files:

C:\Documents and Settings\LocalService\Local Settings\Application Data\sLT.exf
%SysDir%\drivers\update18.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\System Information N827\Type: 10010000
HKLM\System\CurrentControlSet\Services\System Information N827\Start: 02000000
HKLM\System\CurrentControlSet\Services\System Information N827\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\System Information N827\DisplayName: System Information N827
HKLM\System\CurrentControlSet\Services\System Information N827\ImagePath: %WinDir%\System32\drivers\update18.exe

Detected by UnHackMe:

UPDATE18.EXE
Default location: %SYSDIR%\DRIVERS\UPDATE18.EXE

Dropper information:
MD5: 742189a79e7f2d55c0a8322e8d55d72c
File size: 194560 bytes

Leave a Reply