Solved! Use PV.EXE (Trojan Delf) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

PV.EXE – Trojan Delf removal

File MD5 Virus Alias
PV.EXE fecd2fe26b74f67b029f42f5dbaf65df Trojan Delf
PV.EXE fecd2fe26b74f67b029f42f5dbaf65df Trojan Generic!rem
PV.EXE fecd2fe26b74f67b029f42f5dbaf65df Trojan, Suspicious File
PV.EXE fecd2fe26b74f67b029f42f5dbaf65df Trojan Generic
PV.EXE fecd2fe26b74f67b029f42f5dbaf65df Trojan Xema
PV.EXE fecd2fe26b74f67b029f42f5dbaf65df Trojan Agent

PV.EXE size: 73728 bytes
PV.EXE hash: FECD2FE26B74F67B029F42F5DBAF65DF

Created files:

%WinDir%\drwtsn32.exe
%WinDir%\ml.exe
%WinDir%\ml.nkd
%WinDir%\ms.exe
%WinDir%\ms.nkd
%WinDir%\nkd.nkd
%WinDir%\ns.exe
%WinDir%\ns.nkd
%WinDir%\pv.exe
%WinDir%\pv.nkd

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Explorer: %WinDir%\drwtsn32.exe

Detected by UnHackMe:

PV.EXE
Default location: %WinDir%\PV.EXE

Dropper information:
MD5: 03ccd38662ea18ff722cf14a7a26aa4c
File size: 489472 bytes

Leave a Reply