Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

MS_UPDATE2.EXE is Backdoor Poison

$
0
0

The program MS_UPDATE2.EXE is used for hidden penetration into PC and its remote administration.
UnHackMe is recommended as a reliable program for solving the problem with MS_UPDATE2.EXE.
Download for free: http://www.unhackme.com

Malware Analysis of MS_UPDATE2.EXE
Full path on a computer: %SysDir%\MS_Update2.exe

Detected by UnHackMe:

MS_UPDATE2.EXE
Default location: %SysDir%\MS_Update2.exe

Removal Results: Success
Number of reboot: 1

MS_UPDATE2.EXE is known as:

Backdoor.Poison, Backdoor ( 00028bd51 ), Backdoor.Darkmoon, Win32.SillyDl.DQU, Trojan.Downloader-24568, Backdoor.Poison.aec, Trojan.Poison.vmzl, Trojan.Agent.Gen-Frauder, Backdoor:W32.PoisonIvy.GI, BackDoor.Poison.686, Backdoor.Poison.Pg (v), Troj.Keylog-JV, Backdoor.Poison.bp, Hack.Poison.pg.5844, Backdoor.Poison.E, Backdoor.Poison.8704.M, Win-Trojan.Agent.8192.EL, Backdoor.Poison.Az, Win32.Poison.NAE, NORMAL:Hack.Agent.fb.1510270, Virus.Poison, W32.Poison.CWKQ.tr.bdr, Win32.Agent.BB, Bck.Poison.E

MS_UPDATE2.EXE hash:

  • MD5: 7520d35fecac6d2a14137ce97adcbe73
The file tries to download information from some web sites.
How to quickly detect MS_UPDATE2.EXE presence?
Registry:
  • HKLM\Software\Microsoft\Active Setup\Installed Components\{92BEFA62-41ED-F8DC-0F93-4C94A5E549B5}\StubPath: “%SysDir%\MS_Update2.exe”
Files:
  • %SysDir%\MS_Update2.exe


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>