EFupdater.exe
Express Files Updater by Faglaro Enterprises Limited (Signed)
Warning 11 antivirus scanners has detected malware in various versions of EFupdater.exe.
Overview
efupdater.exe has 4 known versions, the most recent one is 1, 0, 0, 6. efupdater.exe is run as a standard windows process with the logged in user's account privileges. The process utilizes the Windows Task Scheduler to automatically launch the file as a process when a user logs into Windows. The average file size is about 195.79 KB. It is an authenticode code-signed executable issued to Faglaro Enterprises Limited by the certification authority COMODO CA Limited. Some variations of the file have been seen to be installed with the program ExpressFiles from Express Solutions. During the process's lifecycle, the typical CPU resource utilization is about 0.0004% including both foreground and background operations, the average private memory consumption is about 8.61 MB with the maximum memory reaching around 11.02 MB. Addionally, typically read and write I/O disk operations is about 10.64 KB per minute for reads and 0 Bytes per minute for writes. 
What is efupdater.exe?
Express Files Updater (efupdater.exe) is a program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.
About efupdater.exe (from Faglaro Enterprises Limited)
“It's all-in-one product. Easy to use instant built-in search tool usefully sorts your results and download manager is so handy. With our prod- uct you can find any content of any subject that interest”
|  Details
 | 
| File name: | efupdater.exe | 
| Publisher: | http://www.express-files.com/ | 
| Product name: | Express Files Updater | 
| Typical file path: | C:\Program Files\expressfiles\efupdater.exe | 
| Certificate | 
| Issued to: | Faglaro Enterprises Limited | 
| Authority (CA): | COMODO CA Limited | 
| Effective date: | Friday, December 16, 2011 | 
| Expiration date: | Sunday, December 16, 2012 | 
 Programs installed in
Programs installed in
(Note, the programs listed below are for all versions of Express Files Updater.)
“No settings, no complications, unimaginable speed, with minimum effort and maximum simplicity! User-friendly interface anyone can manage. Built-in instant search tool with an amazingly intelligent alg...”
 
 Behaviors
Behaviors
(Note, the behaviors below are for all versions of efupdater.exe, select a unique version for details.)
Scheduled tasks
- The job 'Express Files Updater' runs on logon in the path 'C:\WINDOWS\Tasks\Express Files Updater.job'
- The job 'Express FilesUpdate' runs on logon in the path '\Express FilesUpdate'
- Entry path '\Express FilesUpdate'
- Entry path '\Express Files Updater'
- Entry path 'C:\WINDOWS\Tasks\Express FilesUpdate.job'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
- Login entry path 'C:\WINDOWS\Tasks\Express Files Updater.job'
- Login entry path '\Express FilesUpdate'
- Login entry path '\Express Files Updater'
- Login entry path 'C:\WINDOWS\Tasks\Express FilesUpdate.job'
 Malware detections
Malware detections
Based on 40+ industry antivirus scanners, 11 of them detected the following malware.
| Antivirus engine | Engine version | Detection | File version | 
| Dr.Web | 8.13.4.10 | Tool.DownLoader.52 | 1,0,0,0 | 
| Dr.Web | 7.0.4.09250 | Tool.DownLoader.52 | 1,0,0,0 | 
| Dr.Web | 8.13.4.17 | Tool.DownLoader.52 | 1, 0, 0, 6 | 
| Emsisoft Anti-Malware | 3.0.0.575 | Trojan.Win32.YourFileDownloader.AMN (A) | 1, 0, 0, 6 | 
| eSafe | 7.0.17.0 | Win32.Trojan | 1, 0, 0, 6 | 
| ESET NOD32 | 7.8137 | a variant of Win32/YourFileDownloader.B | 1,0,0,0 | 
| ESET NOD32 | 7.8224 | a variant of Win32/YourFileDownloader.B | 1, 0, 0, 6 | 
| ESET NOD32 | 7.8267 | a variant of Win32/YourFileDownloader.B | 1,0,0,0 | 
| Trend Micro HouseCall | 9.700.0.1001 | TROJ_GEN.F47V0721 | 1,0,0,0 | 
| VIPRE Antivirus | 16818 | ExpressFiles Installer (fs) | 1, 0, 0, 6 | 
| VIPRE Antivirus | 17180 | ExpressFiles Installer (fs) | 1,0,0,0 | 
 All file variations of efupdater.exe
All file variations of efupdater.exe
 Distribution by Windows OS
Distribution by Windows OS
| OS version | distribution | 
| Windows 7 Ultimate | 32.35% |  | 
| Microsoft Windows XP | 29.41% |  | 
| Windows 7 Home Premium | 14.71% |  | 
| Windows Vista Home Premium | 11.76% |  | 
| Windows 8 Pro | 8.82% |  | 
| Windows 8 Pro with Media Center | 2.94% |  | 
 Distribution by country
Distribution by country
United Kingdom installs about 23.53% of Express Files Updater.
 Distribution by PC manufacturer
Distribution by PC manufacturer
| PC Manufacturer | distribution | 
| Acer | 23.53% |  | 
| Dell | 23.53% |  | 
| Toshiba | 23.53% |  | 
| American Megatrends | 17.65% |  | 
| Hewlett-Packard | 11.76% |  |