WEBKIT2WEBPROCESS.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

WEBKIT2WEBPROCESS.EXE – Trojan Delf removal

FileMD5Virus Alias
WEBKIT2WEBPROCESS.EXE 3c62ebf4bfa86dd1f77b384645243532 Trojan Delf
WEBKIT2WEBPROCESS.EXE 3c62ebf4bfa86dd1f77b384645243532 Trojan SuspiciousFile
WEBKIT2WEBPROCESS.EXE 3c62ebf4bfa86dd1f77b384645243532 Backdoor Maximus
WEBKIT2WEBPROCESS.EXE 3c62ebf4bfa86dd1f77b384645243532 Trojan Agent
WEBKIT2WEBPROCESS.EXE 3c62ebf4bfa86dd1f77b384645243532 Trojan Delphi
WEBKIT2WEBPROCESS.EXE 3c62ebf4bfa86dd1f77b384645243532 Backdoor IRCBot

WEBKIT2WEBPROCESS.EXE size: 1907320 bytes
WEBKIT2WEBPROCESS.EXE hash: 3C62EBF4BFA86DD1F77B384645243532

Created files:

%SysDir%\DC++ Share\ClearPluginsCache.exe
%SysDir%\DC++ Share\Far.exe
%SysDir%\DC++ Share\msinfo32.exe
%SysDir%\DC++ Share\plutil.exe
%SysDir%\DC++ Share\sapisvr.exe
%SysDir%\DC++ Share\WebKit2WebProcess.exe
%SysDir%\sIRC4.exe
%SysDir%\xdccPrograms\APSDaemon.exe
%SysDir%\xdccPrograms\defaults.exe
%SysDir%\xdccPrograms\distnoted.exe
%SysDir%\xdccPrograms\KillOK.exe
%SysDir%\xdccPrograms\Network Setup Wizard.exe
%SysDir%\xdccPrograms\Opera_1161_int_Setup.exe
%SysDir%\xdccPrograms\SafariSetup.exe
%SysDir%\xdccPrograms\SoftwareUpdate.exe
%SysDir%\xdccPrograms\Wireless Network Setup Wizard.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe sIRC4.exe

Detected by UnHackMe:

WEBKIT2WEBPROCESS.EXE
Default location: %SYSDIR%\DC++ SHARE\WEBKIT2WEBPROCESS.EXE

Dropper information:
MD5: 3c62ebf4bfa86dd1f77b384645243532
File size: 1907320 bytes

Leave a Reply