Solved! Use RUNDLL32SRV.EXE (Backdoor IRCNite) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

RUNDLL32SRV.EXE – Backdoor IRCNite removal

File MD5 Virus Alias
RUNDLL32SRV.EXE 7b9c72733b615919a28f1011958b818f Backdoor IRCNite
RUNDLL32SRV.EXE 7b9c72733b615919a28f1011958b818f Trojan, Suspicious File
RUNDLL32SRV.EXE 7b9c72733b615919a28f1011958b818f Trojan XPACK
RUNDLL32SRV.EXE 7b9c72733b615919a28f1011958b818f Trojan Malware.Obscu
RUNDLL32SRV.EXE 7b9c72733b615919a28f1011958b818f Trojan Generic
RUNDLL32SRV.EXE 7b9c72733b615919a28f1011958b818f Trojan Generic.KD

RUNDLL32SRV.EXE size: 40448 bytes
RUNDLL32SRV.EXE hash: 7B9C72733B615919A28F1011958B818F

Created files:

%Program Files%\Microsoft\DesktopLayer.exe
%SysDir%\rundll32Srv.exe
%Common AppData%\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe
%Local AppData%\Google\Chrome\Application\17.0.963.56\avcodec-53.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\avformat-53.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\avutil-51.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: c:\windows\System32\userinit.exe,,c:\program files\Microsoft\desktoplayer.exe

Detected by UnHackMe:

RUNDLL32SRV.EXE
Default location: %SYSDIR%\RUNDLL32SRV.EXE

Dropper information:
MD5: 06357d06f10e33fdded3f39ba1978ab8
File size: 258048 bytes

Leave a Reply