Solved! Use V3VATE32.DLL (Trojan Banker) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

V3VATE32.DLL – Trojan Banker removal

File MD5 Virus Alias
V3VATE32.DLL b014ddfdc552b480445b010e7231eef2 Trojan Banker
V3VATE32.DLL b014ddfdc552b480445b010e7231eef2 Trojan Win32-Spy
V3VATE32.DLL b014ddfdc552b480445b010e7231eef2 Trojan Artemis
V3VATE32.DLL b014ddfdc552b480445b010e7231eef2 Trojan Generic
V3VATE32.DLL b014ddfdc552b480445b010e7231eef2 Trojan Agent

V3VATE32.DLL size: 73728 bytes
V3VATE32.DLL hash: B014DDFDC552B480445B010E7231EEF2

Created files:

%SysDir%\V3Vate32.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\V3Vate\Type: 10000000
HKLM\System\CurrentControlSet\Services\V3Vate\Start: 02000000
HKLM\System\CurrentControlSet\Services\V3Vate\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\V3Vate\DisplayName: V3 Vate
HKLM\System\CurrentControlSet\Services\V3Vate\ImagePath: 2500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C0073007600630068006F007300740020002D006B0020005600330056006100740065000000
HKLM\System\CurrentControlSet\Services\V3Vate\Description: Vate mornitor for V3 AntiVirius
HKLM\System\CurrentControlSet\Services\V3Vate\Group: Com Infrastructure
HKLM\System\CurrentControlSet\Services\V3Vate\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\V3Vate\FailureAction: 00000000000000000000000001000000000000000200000060EA0000
HKLM\System\CurrentControlSet\Services\V3Vate\Parameters\ServiceDll: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C00560033005600610074006500330032002E0064006C006C000000
HKLM\System\CurrentControlSet\Services\V3Vate\Parameters\ServiceMain: UnicodeMain

Detected by UnHackMe:

V3VATE32.DLL
Default location: %SYSDIR%\V3VATE32.DLL

Dropper information:
MD5: ca5e67537ea090f44e591ae523efea57
File size: 43905 bytes

Leave a Reply