bandxtey.exe

The executable bandxtey.exe has been detected as malware by 30 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “Google Update Service”.
MD5:
f3b22ec7a4db48b0761eb185e1c626ba

SHA-1:
688aea01b23166a7184a964eb0c6a5c70874e88b

SHA-256:
de198e0440f06b5772cecefd5701ed226ef21205e4cdee66e17987e9c5f00aa4

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/26/2024 8:31:45 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2169565
701

Agnitum Outpost
Trojan.Staser
7.1.1

AhnLab V3 Security
Trojan/Win32.Dyzap
2015.02.25

Avira AntiVirus
TR/Samca.4816897
7.11.212.96

avast!
Win32:Malware-gen
2014.9-150306

AVG
Ransomer
2016.0.3179

Baidu Antivirus
Trojan.Win32.Staser
4.0.3.1536

Bitdefender
Trojan.GenericKD.2169565
1.0.20.325

Dr.Web
Trojan.Dyre.43
9.0.1.065

Emsisoft Anti-Malware
Trojan.GenericKD.2169565
8.15.03.06.06

ESET NOD32
Win32/Battdil
9.11227

Fortinet FortiGate
W32/Staser.AZWV!tr
3/6/2015

F-Secure
Trojan.GenericKD.2169565
11.2015-06-03_6

G Data
Trojan.GenericKD.2169565
15.3.25

IKARUS anti.virus
Trojan-Spy.Agent
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.198.15071

Kaspersky
Trojan.Win32.Staser
14.0.0.2389

Malwarebytes
Trojan.Agent.ED
v2015.03.06.06

McAfee
RDN/Generic PWS.y!bcr
5600.6835

Microsoft Security Essentials
PWS:Win32/Dyzap.M
1.1.11400.0

MicroWorld eScan
Trojan.GenericKD.2169565
16.0.0.195

NANO AntiVirus
Trojan.Win32.Staser.dnzpbi
0.30.0.296

nProtect
Trojan.GenericKD.2169565
15.02.24.01

Panda Antivirus
Trj/CI.A
15.03.06.06

Sophos
Mal/Generic-L
4.98

Trend Micro House Call
TROJ_CRYPT.BMYU
7.2.65

Trend Micro
TROJ_CRYPT.BMYU
10.465.06

VIPRE Antivirus
Trojan.Win32.Generic
37866

ViRobot
Trojan.Win32.A.Staser.519168[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Staser.Win32.3093
2.0.0.2079

File size:
507 KB (519,168 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\bandxtey.exe

File PE Metadata
Compilation timestamp:
12/20/2002 1:56:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:P30gMKssTx3rDwVL3UX7d6vNl40qPyhyG9QG/nS:cKFnELEXIlQ4KG

Entry address:
0x4BCBB

Entry point:
64, A1, 00, 00, 00, 00, 55, 8B, EC, 6A, FF, 68, A0, 0E, 46, 00, 68, 90, B9, 45, 00, 50, A1, 68, BA, 47, 00, 64, 89, 25, 00, 00, 00, 00, 8B, 0D, 08, C0, 45, 00, 83, EC, 6C, 89, 01, 8B, 15, 64, BA, 47, 00, A1, 0C, C0, 45, 00, 53, 56, 57, 89, 65, E8, 89, 10, E8, C4, FE, FE, FF, 8D, 55, D8, 8D, 45, D4, FF, 35, 60, BA, 47, 00, 52, 50, 8D, 4D, D0, 51, E8, 5B, AB, 00, 00, 83, C4, 10, 68, 04, C1, 45, 00, 68, 00, C1, 45, 00, E8, 43, AB, 00, 00, 83, C4, 08, C7, 45, FC, 00, 00, 00, 00, A1, 18, C0, 45, 00, 8B, 30, 8A...
 
[+]

Developed / compiled with:
Microsoft Visual C, 2.0

Code size:
363 KB (371,712 bytes)

Service
Display name:
Google Update Service

Service name:
googleupdate

Type:
Win32OwnProcess


Remove bandxtey.exe - Powered by Reason Core Security