Solved! Use DESKTOPLAYERSRVSRV.EXE (Worm AMN) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

DESKTOPLAYERSRVSRV.EXE – Worm AMN removal

File MD5 Virus Alias
DESKTOPLAYERSRVSRV.EXE 48599263b7948935028a61749b0cbc88 Worm AMN
DESKTOPLAYERSRVSRV.EXE 48599263b7948935028a61749b0cbc88 Trojan Krap
DESKTOPLAYERSRVSRV.EXE 48599263b7948935028a61749b0cbc88 Trojan Agent
DESKTOPLAYERSRVSRV.EXE 48599263b7948935028a61749b0cbc88 Trojan ZBot

DESKTOPLAYERSRVSRV.EXE size: 172032 bytes
DESKTOPLAYERSRVSRV.EXE hash: 48599263B7948935028A61749B0CBC88

Created files:

%Program Files%\Microsoft\DesktopLayer.exe
%Program Files%\Microsoft\DesktopLayerSrv.exe
%Program Files%\Microsoft\DesktopLayerSrvSrv.exe
%Common AppData%\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe
%Local AppData%\Google\Chrome\Application\17.0.963.56\avcodec-53.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\avformat-53.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\avutil-51.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: c:\windows\System32\userinit.exe,,c:\program files\Microsoft\desktoplayer.exe

Detected by UnHackMe:

DESKTOPLAYERSRVSRV.EXE
Default location: %PROGRAM FILES%\MICROSOFT\DESKTOPLAYERSRVSRV.EXE

Dropper information:
MD5: 012290f689a98e30fd50ba74bacde350
File size: 287744 bytes

Leave a Reply