Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

GOOGLEUPDATE.EXE is Rootkit ZeroAccess

$
0
0

Rootkit GOOGLEUPDATE.EXE is software that enables continued privileged access to a computer while actively hiding its presence.
Detection and removal of GOOGLEUPDATE.EXE may be a very difficult process.
You should use anti-rootkit software to fix the GOOGLEUPDATE.EXE problem.

Malware Analysis of GOOGLEUPDATE.EXE
Full path on a computer: C:\Users\test\AppData\Local\Google\Desktop\Install\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\???\???\???\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\GoogleUpdate.exe

Detected by UnHackMe:

Item Name: ?etadpug\46,32,101,0,116,0,97,0,100,0,112,0,117,0,103,0(16)
Author:
Related File: “%Program Files%\Google\Desktop\Install\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\ \…\???\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\GoogleUpdate.exe” <
Type: Zero Access Rootkit

Item Name: Google Update{71,0,111,0,111,0,103,0,108,0,101,0,32,0,85,0(16)}
Author:
Related File: “C:\Users\test\AppData\Local\Google\Desktop\Install\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\???\???\???\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\GoogleUpdate.exe” >
Type: Zero Access Rootkit

Removal Results: Success
Number of reboot: 1

GOOGLEUPDATE.EXE is known as:

Rootkit.ZeroAccess, Backdoor.ZAccess.6YTA+hLduUs, Trojan.Agent.Gen-Kazy, BackDoor.Maxplus.12847, TR.Kazy.213647, Mal.EncPk-AKZ, TrojanDropper.Sirefef, Backdoor.ZAccess, Win32.Sirefef.FY, Crypt_s.CFG, Trj.dtcontx.G

GOOGLEUPDATE.EXE hash:

  • MD5: 762f7891f661abbd755620148dbdcb8a
How to quickly detect GOOGLEUPDATE.EXE presence? 
Registry:
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Google Update: “”C:\Users\test\AppData\Local\Google\Desktop\Install\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\???\???\???\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\GoogleUpdate.exe” >”
  • HKLM\System\CurrentControlSet\services\?etadpug\ImagePath: “”C:\\Program Files\\Google\\Desktop\\Install\\{b191330c-415d-5883-57c7-9de300728739}\\ \\ \\???\\{b191330c-415d-5883-57c7-9de300728739}\\GoogleUpdate.exe” <”
Folders:
  • C:\Users\test\AppData\Local\Google\Desktop\Install\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\???
  • C:\\Program Files\\Google\\Desktop\\Install\\{b191330c-415d-5883-57c7-9de300728739}\\ \\ \\???\\{b191330c-415d-5883-57c7-9de300728739}
Files:
  • %Program Files%\Google\Desktop\Install\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\ \…\???\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\GoogleUpdate.exe
  • C:\Users\test\AppData\Local\Google\Desktop\Install\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\???\???\???\{e2b7ffc4-ebef-d2ee-173d-cb3acc78628d}\GoogleUpdate.exe


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>