Solved! Use OPERA_1161_INT_SETUP.EXE (Trojan Delf) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

OPERA_1161_INT_SETUP.EXE – Trojan Delf removal

File MD5 Virus Alias
OPERA_1161_INT_SETUP.EXE 115129a3942c0d868bf443dd451fe38e Trojan Delf
OPERA_1161_INT_SETUP.EXE 115129a3942c0d868bf443dd451fe38e Trojan Hlux
OPERA_1161_INT_SETUP.EXE 115129a3942c0d868bf443dd451fe38e Trojan Eldorado
OPERA_1161_INT_SETUP.EXE 115129a3942c0d868bf443dd451fe38e Trojan Delphi
OPERA_1161_INT_SETUP.EXE 115129a3942c0d868bf443dd451fe38e Trojan Crypt
OPERA_1161_INT_SETUP.EXE 115129a3942c0d868bf443dd451fe38e Backdoor IRCBot

OPERA_1161_INT_SETUP.EXE size: 10625584 bytes
OPERA_1161_INT_SETUP.EXE hash: 115129A3942C0D868BF443DD451FE38E

Created files:

%SysDir%\sIRC4.exe
%SysDir%\xdccPrograms\KillOK.exe
%SysDir%\xdccPrograms\Network Setup Wizard.exe
%SysDir%\xdccPrograms\Opera_1161_int_Setup.exe
%SysDir%\xdccPrograms\SafariSetup.exe
%SysDir%\xdccPrograms\Wireless Network Setup Wizard.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe sIRC4.exe

Detected by UnHackMe:

OPERA_1161_INT_SETUP.EXE
Default location: %SYSDIR%\XDCCPROGRAMS\OPERA_1161_INT_SETUP.EXE

Dropper information:
MD5: 1a42d7e386c341fafe05c4ddd0c0b9a1
File size: 444855 bytes

Leave a Reply