Solved! Use UPDATER.EXE (Trojan Downloader) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

UPDATER.EXE – Trojan Downloader removal

FileMD5Virus Alias
UPDATER.EXE f204570dc17fa6fa3808427e6a87923a Trojan Downloader

UPDATER.EXE size: 186952 bytes
UPDATER.EXE hash: F204570DC17FA6FA3808427E6A87923A

Created files:

%Program Files%\Mozilla Firefox\distribution\bundles\s
%AppData%\ARHome\Updater.exe
%AppData%\VolIE\FoxPro_32.dll
%AppData%\VolIE\FoxPro_64.dll
%Local AppData%\Dgn0G.vbs
%SysDir%\GroupPolicy\Machine\Registry.pol

Autostart registry keys:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ArHome: %WinDir%\System32\config\Systemprofile\Application Data\ARHome\Updater.exe

Detected by UnHackMe:

UPDATER.EXE
Default location: %APPDATA%\ARHOME\UPDATER.EXE

Dropper information:
MD5: 9beb0e9b32170e2f3209d9803b56796b
File size: 716360 bytes

Leave a Reply