Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

WMDUPDATE.EXE is Trojan Gaobot

$
0
0

We checked some samples of WMDUPDATE.EXE and detected the file WMDUPDATE.EXE as threat.
Remove the WMDUPDATE.EXE file from your computer right now.
Removal tool: http://www.unhackme.com

Malware Analysis of WMDUPDATE.EXE
Full path on a computer: %WinDir%\wmdupdate.exe

Detected by UnHackMe:

WMDUPDATE.EXE
Default location: %WinDir%\wmdupdate.exe

Removal Results: Success
Number of reboot: 1

WMDUPDATE.EXE is known as:

Trojan.Gaobot, a variant of Win32.AutoRun.IRCBot.DI, Backdoor.IRCBot, Exploit.MS04-011, Backdoor.IRCBot.AuB

WMDUPDATE.EXE hash:

  • MD5: 242c05b4eb3500fb2b59104b52cb1494
How to quickly detect WMDUPDATE.EXE presence?
Registry:
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Data Serivce: “wmdupdate.exe”
Files:
  • %WinDir%\wmdupdate.exe


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>