Solved! Use SERVER.EXE (Trojan Delf) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SERVER.EXE – Trojan Delf removal

File MD5 Virus Alias
SERVER.EXE cc3515d41c52aef7194ca342e93e7891 Trojan Delf
SERVER.EXE cc3515d41c52aef7194ca342e93e7891 Trojan XPACK
SERVER.EXE cc3515d41c52aef7194ca342e93e7891 Trojan Eldorado
SERVER.EXE cc3515d41c52aef7194ca342e93e7891 Backdoor Poison
SERVER.EXE cc3515d41c52aef7194ca342e93e7891 Trojan Siggen
SERVER.EXE cc3515d41c52aef7194ca342e93e7891 Trojan Agent

SERVER.EXE size: 33792 bytes
SERVER.EXE hash: CC3515D41C52AEF7194CA342E93E7891

Created files:

%SysDir%\InstallDir\Server.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{Q182OA82-J24Y-RHXB-L47M-FE8V80E8Q6GH}\StubPath: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0049006E007300740061006C006C004400690072005C005300650072007600650072002E006500780065000000
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\HKLM: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0049006E007300740061006C006C004400690072005C005300650072007600650072002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\HKCU: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0049006E007300740061006C006C004400690072005C005300650072007600650072002E006500780065000000

Detected by UnHackMe:

SERVER.EXE
Default location: %SYSDIR%\INSTALLDIR\SERVER.EXE

Dropper information:
MD5: cc3515d41c52aef7194ca342e93e7891
File size: 33792 bytes

Leave a Reply