Solved! Use SERVER.EXE (Trojan Delf) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SERVER.EXE – Trojan Delf removal

FileMD5Virus Alias
SERVER.EXE 43c89d639c5f1033aca75fff2f7d09e9 Trojan Delf
SERVER.EXE 43c89d639c5f1033aca75fff2f7d09e9 Trojan XPACK
SERVER.EXE 43c89d639c5f1033aca75fff2f7d09e9 Trojan Eldorado
SERVER.EXE 43c89d639c5f1033aca75fff2f7d09e9 Trojan Downloader
SERVER.EXE 43c89d639c5f1033aca75fff2f7d09e9 Backdoor Poison
SERVER.EXE 43c89d639c5f1033aca75fff2f7d09e9 Worm Autorun

SERVER.EXE size: 67072 bytes
SERVER.EXE hash: 43C89D639C5F1033ACA75FFF2F7D09E9

Created files:

%WinDir%\InstallDir\Server.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{5460C4DF-B266-909E-CB58-E32B79832EB2}\StubPath: 43003A005C00570049004E0044004F00570053005C0049006E007300740061006C006C004400690072005C005300650072007600650072002E006500780065000000
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\HKLM: 43003A005C00570049004E0044004F00570053005C0049006E007300740061006C006C004400690072005C005300650072007600650072002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\HKCU: 43003A005C00570049004E0044004F00570053005C0049006E007300740061006C006C004400690072005C005300650072007600650072002E006500780065000000

Detected by UnHackMe:

SERVER.EXE
Default location: %WinDir%\INSTALLDIR\SERVER.EXE

Dropper information:
MD5: 43c89d639c5f1033aca75fff2f7d09e9
File size: 67072 bytes

Leave a Reply