SYSFILE.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SYSFILE.EXE – Trojan Delf removal

FileMD5Virus Alias
SYSFILE.EXE 057c0942d92c917ac87fb6307b2f3ae1 Trojan Delf
SYSFILE.EXE 057c0942d92c917ac87fb6307b2f3ae1 Trojan Artemis
SYSFILE.EXE 057c0942d92c917ac87fb6307b2f3ae1 Trojan Generic
SYSFILE.EXE 057c0942d92c917ac87fb6307b2f3ae1 Trojan Eldorado
SYSFILE.EXE 057c0942d92c917ac87fb6307b2f3ae1 Trojan Downloader
SYSFILE.EXE 057c0942d92c917ac87fb6307b2f3ae1 Trojan Agent

SYSFILE.EXE size: 194560 bytes
SYSFILE.EXE hash: 057C0942D92C917AC87FB6307B2F3AE1

Created files:

C:\Documents and Settings\LocalService\Local Settings\Application Data\sLT.exf
%SysDir%\drivers\sysfile.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\SYSFILE\Type: 10010000
HKLM\System\CurrentControlSet\Services\SYSFILE\Start: 02000000
HKLM\System\CurrentControlSet\Services\SYSFILE\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\SYSFILE\DisplayName: SYSFILE
HKLM\System\CurrentControlSet\Services\SYSFILE\ImagePath: %WinDir%\System32\drivers\sysfile.exe

Detected by UnHackMe:

SYSFILE.EXE
Default location: %SYSDIR%\DRIVERS\SYSFILE.EXE

Dropper information:
MD5: 057c0942d92c917ac87fb6307b2f3ae1
File size: 194560 bytes

Leave a Reply