ANTIVAR.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

ANTIVAR.EXE – Trojan Delf removal

FileMD5Virus Alias
ANTIVAR.EXE 428b7f03f2e342b53837c7a0fec97625 Trojan Delf
ANTIVAR.EXE 428b7f03f2e342b53837c7a0fec97625 Trojan Generic
ANTIVAR.EXE 428b7f03f2e342b53837c7a0fec97625 Trojan Eldorado
ANTIVAR.EXE 428b7f03f2e342b53837c7a0fec97625 Trojan Downloader
ANTIVAR.EXE 428b7f03f2e342b53837c7a0fec97625 Trojan Bancos
ANTIVAR.EXE 428b7f03f2e342b53837c7a0fec97625 Trojan Agent

ANTIVAR.EXE size: 177152 bytes
ANTIVAR.EXE hash: 428B7F03F2E342B53837C7A0FEC97625

Created files:

C:\Documents and Settings\LocalService\Local Settings\Application Data\sLT.exf
%SysDir%\antivar.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\ServerNabs4\Type: 10010000
HKLM\System\CurrentControlSet\Services\ServerNabs4\Start: 02000000
HKLM\System\CurrentControlSet\Services\ServerNabs4\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\ServerNabs4\DisplayName: ServerNabs4
HKLM\System\CurrentControlSet\Services\ServerNabs4\ImagePath: %WinDir%\System32\antivar.exe

Detected by UnHackMe:

ANTIVAR.EXE
Default location: %SYSDIR%\ANTIVAR.EXE

Dropper information:
MD5: 428b7f03f2e342b53837c7a0fec97625
File size: 177152 bytes

Leave a Reply