EFupdater.exe
Express Files Updater by Faglaro Enterprises Limited (Signed)
Version: | 1,0,0,0 |
MD5: | 3cffe856d6c054b04da4c0a84d95bf6e |
SHA1: | 6ac9784405f19c54c94812dbc4f6d1e3512f38f5 |
SHA256: | 22382682af13585fb26b2695269b5193c30c618022314ccbbda6299ba4c158b3 |
Warning 3 antivirus scanners has detected malware.
What is EFupdater.exe?
Express Files Updater (efupdater.exe) is a program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.
About EFupdater.exe (from Faglaro Enterprises Limited)
“It's all-in-one product. Easy to use instant built-in search tool usefully sorts your results and download manager is so handy. With our prod- uct you can find any content of any subject that interest”
Overview
efupdater.exe is malware that executes as a process under the SYSTEM account with extensive privileges (the system and the administrator accounts have the same file privileges). It is an auto-starting process that used the Windows Task Scheduler service to load when the user logs into Windows (sometimes this is required to bypass the UAC protection). It is installed with a couple of know programs including ExpressFiles published by Express Solutions, ExpressFiles from Express Solutions and ExpressFiles by Express Solutions.
Details
File name: | efupdater.exe |
Publisher: | http://www.express-files.com/ |
Product name: | Express Files Updater |
Typical file path: | C:\Program Files\expressfiles\efupdater.exe |
File version: | 1,0,0,0 |
Size: | 195.65 KB (200,344 bytes) |
Certificate |
Issued to: | Faglaro Enterprises Limited |
Authority (CA): | COMODO CA Limited |
Effective date: | Friday, December 16, 2011 |
Expiration date: | Sunday, December 16, 2012 |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | Yes |
.NET CLR: | No |
More details
Programs
The following programs will install this file
“No settings, no complications, unimaginable speed, with minimum effort and maximum simplicity! User-friendly interface anyone can manage. Built-in instant search tool with an amazingly intelligent algorithm! It's absolutely free. And, we are con- stantly working to make our product better. Ask why? It's simple! We like to make the Internet better, and staying there pleasant. It's totally unique. Very simple inter- face is specifically d...”
Behaviors
Scheduled tasks
- The job 'Express Files Updater' runs on logon in the path 'C:\WINDOWS\Tasks\Express Files Updater.job'
- The job 'Express FilesUpdate' runs on logon in the path '\Express FilesUpdate'
- Entry path '\Express FilesUpdate'
- Entry path '\Express Files Updater'
- Entry path 'C:\WINDOWS\Tasks\Express FilesUpdate.job'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
- Login entry path 'C:\WINDOWS\Tasks\Express Files Updater.job'
- Login entry path '\Express FilesUpdate'
- Login entry path '\Express Files Updater'
- Login entry path 'C:\WINDOWS\Tasks\Express FilesUpdate.job'
Malware detections
Based on 40+ industry antivirus scanners, 3 of them detected the following malware.
Antivirus engine | Engine version | Detection |
Dr.Web |
8.13.4.10 |
Tool.DownLoader.52 |
ESET NOD32 |
7.8137 |
a variant of Win32/YourFileDownloader.B |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.F47V0721 |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00030590% | |
Kernel CPU: | 0.00015923% | |
User CPU: | 0.00014668% | |
Kernel CPU time: | 203 ms/min | |
Memory |
Private memory: | 8.05 MB | |
Private (maximum): | 10.76 MB | |
Private (minimum): | 10.71 MB | |
Non-paged memory: | 8.05 MB | |
Virtual memory: | 48.23 MB | |
Virtual memory (peak): | 51.51 MB | |
Working set: | 10.75 MB | |
Working set (peak): | 10.77 MB | |
Page faults: | 4,147/min | |
I/O |
I/O read transfer: | 2.15 KB/sec | |
I/O read operations: | 1/sec | |
I/O write transfer: | 0 Bytes/sec | |
I/O write operations: | 1/sec | |
I/O other transfer: | 11 Bytes/sec | |
I/O other operations: | 1/sec | |
Resource allocations |
Threads: | 2 | |
Handles: | 153 | |
GUI GDI count: | 33 | |
GUI USER count: | 5 | |
Process properties
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
32.35% |
|
Microsoft Windows XP |
29.41% |
|
Windows 7 Home Premium |
14.71% |
|
Windows Vista Home Premium |
11.76% |
|
Windows 8 Pro |
8.82% |
|
Windows 8 Pro with Media Center |
2.94% |
|
Distribution by country
United Kingdom installs about 23.53% of Express Files Updater.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Acer |
23.53% |
|
Dell |
23.53% |
|
Toshiba |
23.53% |
|
American Megatrends |
17.65% |
|
Hewlett-Packard |
11.76% |
|