Solved! Use SERVER.EXE (Trojan Delf) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SERVER.EXE – Trojan Delf removal

File MD5 Virus Alias
SERVER.EXE 823446c8415260ca44bd2109907e4716 Trojan Delf
SERVER.EXE 823446c8415260ca44bd2109907e4716 Trojan Genome
SERVER.EXE 823446c8415260ca44bd2109907e4716 Trojan Hllw
SERVER.EXE 823446c8415260ca44bd2109907e4716 Trojan Eldorado
SERVER.EXE 823446c8415260ca44bd2109907e4716 Trojan Graftor
SERVER.EXE 823446c8415260ca44bd2109907e4716 Trojan Agent

SERVER.EXE size: 438272 bytes
SERVER.EXE hash: 823446C8415260CA44BD2109907E4716

Created files:

C:\directory\CyberGate\install\server.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{43YPBM07-Q23K-WC1K-57Y8-0W12XE6FJ000}\StubPath: c:\directory\CyberGate\install\server.exe Restart
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: 63003A005C006400690072006500630074006F00720079005C004300790062006500720047006100740065005C0069006E007300740061006C006C005C007300650072007600650072002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: 63003A005C006400690072006500630074006F00720079005C004300790062006500720047006100740065005C0069006E007300740061006C006C005C007300650072007600650072002E006500780065000000

Detected by UnHackMe:

SERVER.EXE
Default location: C:\DIRECTORY\CYBERGATE\INSTALL\SERVER.EXE

Dropper information:
MD5: 823446c8415260ca44bd2109907e4716
File size: 438272 bytes

Leave a Reply