update.exe

IconsDB

The executable update.exe has been detected as malware by 6 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. Accoriding to the detections, this has been classified as a kyelogger which is capable of recoring a user's keystrokes.
Publisher:
IconsDB  (signed and verified)

Version:
24.1.15.0

MD5:
38656878a881e6fd514d5d07b3458cfe

SHA-1:
1ae8cf769531a33a665762ae5f2180fd902196cf

SHA-256:
c4cfc5ec1a1d3c1d683a8f8f86cfa44b81c27f0870f30b22af3bd0158f5d8012

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
8/11/2025 4:21:32 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.KeyLogger.28086
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.MSILPerseus.10411
11.5.0.6191

ESET NOD32
MSIL/Injector.MAP trojan
8.0.319.0

F-Secure
Variant.MSILPerseus.10411
5.15.96

Microsoft Security Essentials
Threat.Undefined
1.223.145.0

Norman
Gen:Variant.MSILPerseus.10411
19.05.2016 05:17:13

File size:
583 KB (596,976 bytes)

Product version:
24.1.15.0

Original file name:
tdl.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\update.exe

Digital Signature
Signed by:

Authority:
IconsDB

Valid from:
9/16/2015 5:53:42 PM

Valid to:
9/16/2016 5:53:42 PM

Subject:
CN=www.iconsdb.com, O=IconsDB, L=Lisboa, S=Lisboa, C=PT

Issuer:
CN=www.iconsdb.com, O=IconsDB, L=Lisboa, S=Lisboa, C=PT

Serial number:
00D35D24937EB7AB43

File PE Metadata
Compilation timestamp:
9/24/2015 11:03:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
80.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:PLTihc7NIJ5ufqzefJZuOZsGk6d/HZFpsnJXdcY:vbMefJ4YsGk6PFSnncY

Entry address:
0x92B4E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
579 KB (592,896 bytes)

Scheduled Task
Task name:
Update.exe

Path:
\Update\Update.exe

Trigger:
Logon (Runs on logon)


Remove update.exe - Powered by Reason Core Security