I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
WIN.EXE – Trojan Delf removal
File | MD5 | Virus Alias |
---|---|---|
WIN.EXE | 9727e77abd618c37286a63e980b4da44 | Trojan Delf |
WIN.EXE | 9727e77abd618c37286a63e980b4da44 | Trojan Generic |
WIN.EXE | 9727e77abd618c37286a63e980b4da44 | Trojan CI |
WIN.EXE | 9727e77abd618c37286a63e980b4da44 | Trojan Siggen |
WIN.EXE size: 194560 bytes
WIN.EXE hash: 9727E77ABD618C37286A63E980B4DA44
Created files:
%Program Files%\Hook32.dll
%Program Files%\win.exe
%Program Files%\zui.exe
%SysDir%\MySPI.dll
Autostart registry keys:
HKLM\System\CurrentControlSet\Services\WS2IFSL\Type: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\Start: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\DisplayName: Windows Socket 2.0 Non-IFS Service Provider Support Environment
HKLM\System\CurrentControlSet\Services\WS2IFSL\ImagePath: \SystemRoot\System32\drivers\ws2ifsl.sys
Detected by UnHackMe:
WIN.EXE
Default location: %PROGRAM FILES%\WIN.EXE
Dropper information:
MD5: e9bf0050a83da29233fe5c16fd5cde34
File size: 548721 bytes