SERVER.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SERVER.EXE – Trojan Delf removal

FileMD5Virus Alias
SERVER.EXE 093783db8790aea7b8c91632629e8181 Trojan Delf
SERVER.EXE 093783db8790aea7b8c91632629e8181 Trojan Artemis
SERVER.EXE 093783db8790aea7b8c91632629e8181 Trojan XPACK
SERVER.EXE 093783db8790aea7b8c91632629e8181 Trojan Generic
SERVER.EXE 093783db8790aea7b8c91632629e8181 Trojan Hllw
SERVER.EXE 093783db8790aea7b8c91632629e8181 Trojan CI

SERVER.EXE size: 525824 bytes
SERVER.EXE hash: 093783DB8790AEA7B8C91632629E8181

Created files:

%SysDir%\Large\server.exe
%TEMP%\GRY-XX-X
%TEMP%\uU-GRY-Xx

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{MB3JKSW-Y883-WE0K-IY6U-SL6N6I178}\StubPath: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C004C0061007200670065005C007300650072007600650072002E006500780065000000
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C004C0061007200670065005C007300650072007600650072002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C004C0061007200670065005C007300650072007600650072002E006500780065000000

Detected by UnHackMe:

SERVER.EXE
Default location: %SYSDIR%\LARGE\SERVER.EXE

Dropper information:
MD5: 093783db8790aea7b8c91632629e8181
File size: 525824 bytes

Leave a Reply