Solved! Use FADEFS.EXE (Trojan Delf) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

FADEFS.EXE – Trojan Delf removal

FileMD5Virus Alias
FADEFS.EXE c04f811084086a9180bef837e2b5d113 Trojan Delf
FADEFS.EXE c04f811084086a9180bef837e2b5d113 Trojan Generic
FADEFS.EXE c04f811084086a9180bef837e2b5d113 Trojan Eldorado
FADEFS.EXE c04f811084086a9180bef837e2b5d113 Trojan Agent

FADEFS.EXE size: 703488 bytes
FADEFS.EXE hash: C04F811084086A9180BEF837E2B5D113

Created files:

%Program Files Common%\inove\fadefs.exe
%Program Files Common%\inove\foves.exe
%Program Files Common%\inove\koase\cotsen.dll
%Program Files Common%\inove\koase\czocen.dll
%Temp%\RarSFX0\Setup.EXE
%Temp%\RarSFX0\Storm3_NoAD_v1.6.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\sfcpm\Type: 10000000
HKLM\System\CurrentControlSet\Services\sfcpm\Start: 02000000
HKLM\System\CurrentControlSet\Services\sfcpm\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\sfcpm\DisplayName: System File Cache Pool Maneger
HKLM\System\CurrentControlSet\Services\sfcpm\ImagePath: %Program Files Common%\inove\foves.exe
HKLM\System\CurrentControlSet\Services\sfcpm\Description: System File Cache Pool Maneger

Detected by UnHackMe:

FADEFS.EXE
Default location: %PROGRAM FILES COMMON%\INOVE\FADEFS.EXE

Dropper information:
MD5: a248e75e7fffa5f8ec0bc89d934ce8be
File size: 1885585 bytes

Leave a Reply