DESKTOPLAYERSRV.EXE – Trojan ZBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DESKTOPLAYERSRV.EXE – Trojan ZBot removal

FileMD5Virus Alias
DESKTOPLAYERSRV.EXE ff5e1f27193ce51eec318714ef038bef Trojan ZBot
DESKTOPLAYERSRV.EXE ff5e1f27193ce51eec318714ef038bef Trojan Eldorado
DESKTOPLAYERSRV.EXE ff5e1f27193ce51eec318714ef038bef Worm AMN
DESKTOPLAYERSRV.EXE ff5e1f27193ce51eec318714ef038bef Trojan Krap
DESKTOPLAYERSRV.EXE ff5e1f27193ce51eec318714ef038bef Trojan Agent
DESKTOPLAYERSRV.EXE ff5e1f27193ce51eec318714ef038bef Trojan Kryptik

DESKTOPLAYERSRV.EXE size: 56320 bytes

Created files:

%Program Files%\Microsoft\DesktopLayer.exe
%Program Files%\Microsoft\DesktopLayerSrv.exe
%Common AppData%\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe
%Local AppData%\Google\Chrome\Application\17.0.963.56\avcodec-53.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\avformat-53.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\avutil-51.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: c:\windows\System32\userinit.exe,,19fb73b3242712f18c842297fc1ff3easrv.exe

Detected by UnHackMe:

DESKTOPLAYERSRV.EXE
Default location: %PROGRAM FILES%\MICROSOFT\DESKTOPLAYERSRV.EXE

Dropper information:
MD5: 19fb73b3242712f18c842297fc1ff3ea
File size: 114176 bytes

Leave a Reply