PS.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

PS.EXE – Trojan Delf removal

FileMD5Virus Alias
PS.EXE 2428afa5d60744883c3274ce862b2162 Trojan Delf
PS.EXE 2428afa5d60744883c3274ce862b2162 Trojan SuspiciousFile
PS.EXE 2428afa5d60744883c3274ce862b2162 Trojan Generic
PS.EXE 2428afa5d60744883c3274ce862b2162 Trojan CI
PS.EXE 2428afa5d60744883c3274ce862b2162 Trojan Agent
PS.EXE 2428afa5d60744883c3274ce862b2162 Trojan ADH

PS.EXE size: 953351 bytes
PS.EXE hash: 2428AFA5D60744883C3274CE862B2162

Created files:

%TEMP%\IXP000.TMP\ps.exe
%TEMP%\RarSFX0\pssetup.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0: rundll32.exe %WinDir%\System32\advpack.dll,DelNodeRunDLL32 “%TEMP%\IXP000.TMP\”

Detected by UnHackMe:

PS.EXE
Default location: %TEMP%\IXP000.TMP\PS.EXE

Dropper information:
MD5: b8aac790d86f2e96805dc0c76cd9b15a
File size: 990720 bytes

Leave a Reply