Is the file B245551412.EXE located on your computer? Then your computer is infected.
We do suggest you should remove B245551412.EXE from your computer as soon as possible.
B245551412.EXE is Trojan/Backdoor.
Kill the process B245551412.EXE and remove B245551412.EXE from the Windows startup.
Malware Analysis of B245551412.EXE
Full path on a computer: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-31613554\b245551412.exe
Detected by UnHackMe:
B245551412.EXE
Default location: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-31613554\b245551412.exe
Removal Results: Success
Number of reboot: 1
B245551412.EXE is known as:
Trojan.Lethic.B
B245551412.EXE hash:
- MD5: ab51bf349da7db25c837b1f34740b16b
How to quickly detect B245551412.EXE presence?
Registry:
- HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman: “C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-31613554\b245551412.exe”
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\b255341562: “C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-31613554\b245551412.exe”
- HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: “explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-31613554\b245551412.exe”
Folders:
- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-31613554
Files:
- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-31613554\b245551412.exe
- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-31613554\Desktop.ini