Solved! Use WINKEY.DLL (Trojan Vundo) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

WINKEY.DLL – Trojan Vundo removal

FileMD5Virus Alias
WINKEY.DLL 43e7d9b875c921ba6be38d45540fb9dd Trojan Vundo
WINKEY.DLL 43e7d9b875c921ba6be38d45540fb9dd Trojan Generic
WINKEY.DLL 43e7d9b875c921ba6be38d45540fb9dd Trojan Agent
WINKEY.DLL 43e7d9b875c921ba6be38d45540fb9dd Trojan Crypt

WINKEY.DLL size: 24576 bytes
WINKEY.DLL hash: 43E7D9B875C921BA6BE38D45540FB9DD

Created files:

%WinDir%\services.exe
%WinDir%\system\sservice.exe
%SysDir%\fservice.exe
%SysDir%\winkey.dll

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{5Y99AE78-58TT-11dW-BE53-Y67078979Y}\StubPath: %WinDir%\System\sservice.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\DirectX For Microsoft? Windows: %WinDir%\System32\fservice.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe %WinDir%\System32\fservice.exe

Detected by UnHackMe:

WINKEY.DLL
Default location: %SYSDIR%\WINKEY.DLL

Dropper information:
MD5: 21b7c2cdc62cdd269d6ed507fd8a5759
File size: 2035244 bytes

Leave a Reply