Solved! Use NETWORK SETUP WIZARD.EXE (Trojan Delf) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

NETWORK SETUP WIZARD.EXE – Trojan Delf removal

File MD5 Virus Alias
NETWORK SETUP WIZARD.EXE 6bfc48c74649b1908f210fd71d50d50c Trojan Delf
NETWORK SETUP WIZARD.EXE 6bfc48c74649b1908f210fd71d50d50c Trojan Hlux
NETWORK SETUP WIZARD.EXE 6bfc48c74649b1908f210fd71d50d50c Trojan Eldorado
NETWORK SETUP WIZARD.EXE 6bfc48c74649b1908f210fd71d50d50c Trojan Agent
NETWORK SETUP WIZARD.EXE 6bfc48c74649b1908f210fd71d50d50c Trojan Delphi
NETWORK SETUP WIZARD.EXE 6bfc48c74649b1908f210fd71d50d50c Trojan Crypt

NETWORK SETUP WIZARD.EXE size: 97117 bytes
NETWORK SETUP WIZARD.EXE hash: 6BFC48C74649B1908F210FD71D50D50C

Created files:

%SysDir%\sIRC4.exe
%SysDir%\xdccPrograms\KillOK.exe
%SysDir%\xdccPrograms\Network Setup Wizard.exe
%SysDir%\xdccPrograms\Opera_1161_int_Setup.exe
%SysDir%\xdccPrograms\SafariSetup.exe
%SysDir%\xdccPrograms\SoftwareUpdate.exe
%SysDir%\xdccPrograms\Wireless Network Setup Wizard.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe sIRC4.exe

Detected by UnHackMe:

NETWORK SETUP WIZARD.EXE
Default location: %SYSDIR%\XDCCPROGRAMS\NETWORK SETUP WIZARD.EXE

Dropper information:
MD5: 0eb9122714055815b0566af20e22bbd1
File size: 92582 bytes

Leave a Reply