ANTIVAR.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

ANTIVAR.EXE – Trojan Delf removal

FileMD5Virus Alias
ANTIVAR.EXE 06f96b7ebf6d0b0d377377498a026ae3 Trojan Delf
ANTIVAR.EXE 06f96b7ebf6d0b0d377377498a026ae3 Trojan Generic
ANTIVAR.EXE 06f96b7ebf6d0b0d377377498a026ae3 Trojan Eldorado
ANTIVAR.EXE 06f96b7ebf6d0b0d377377498a026ae3 Trojan Downloader
ANTIVAR.EXE 06f96b7ebf6d0b0d377377498a026ae3 Trojan Bancos
ANTIVAR.EXE 06f96b7ebf6d0b0d377377498a026ae3 Trojan Agent

ANTIVAR.EXE size: 177152 bytes
ANTIVAR.EXE hash: 06F96B7EBF6D0B0D377377498A026AE3

Created files:

C:\Documents and Settings\LocalService\Local Settings\Application Data\sLT.exf
%SysDir%\antivar.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\ServerNabs4\Type: 10010000
HKLM\System\CurrentControlSet\Services\ServerNabs4\Start: 02000000
HKLM\System\CurrentControlSet\Services\ServerNabs4\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\ServerNabs4\DisplayName: ServerNabs4
HKLM\System\CurrentControlSet\Services\ServerNabs4\ImagePath: %WinDir%\System32\antivar.exe

Detected by UnHackMe:

ANTIVAR.EXE
Default location: %SYSDIR%\ANTIVAR.EXE

Dropper information:
MD5: 06f96b7ebf6d0b0d377377498a026ae3
File size: 177152 bytes

Leave a Reply