Process.exe is PWSteal.Bancos.P Trojan. Process.exe steals password and bank information. Adds the value: "process.exe" = "%Windir%\process.exe" to the Windows startup registry keys. Process.exe monitors active Internet Explorer windows. It logs keyboard presses and visited domains. Process.exe sends information to a Web server on the domain of woolenhol.com.