Solved! Use DESKTOPLAYER.EXE (Worm AMN) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

DESKTOPLAYER.EXE – Worm AMN removal

File MD5 Virus Alias
DESKTOPLAYER.EXE 00ab2859f5d7ae8fda7bd8e96f1bcda0 Worm AMN
DESKTOPLAYER.EXE 00ab2859f5d7ae8fda7bd8e96f1bcda0 Trojan Krap
DESKTOPLAYER.EXE 00ab2859f5d7ae8fda7bd8e96f1bcda0 Trojan Agent
DESKTOPLAYER.EXE 00ab2859f5d7ae8fda7bd8e96f1bcda0 Trojan ZBot

DESKTOPLAYER.EXE size: 114176 bytes
DESKTOPLAYER.EXE hash: 00AB2859F5D7AE8FDA7BD8E96F1BCDA0

Created files:

%Program Files%\Microsoft\DesktopLayer.exe
%Program Files%\Microsoft\DesktopLayerSrv.exe
%Common AppData%\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe
%Local AppData%\Google\Chrome\Application\17.0.963.56\avcodec-53.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\avformat-53.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\avutil-51.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome_frame_helper.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome_frame_helper.exe
%Local AppData%\Google\Chrome\Application\17.0.963.56\chrome_launcher.exe
%Local AppData%\Google\Chrome\Application\17.0.963.56\d3dcompiler_43.dll
%Local AppData%\Google\Chrome\Application\17.0.963.56\d3dx9_43.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: c:\windows\System32\userinit.exe,,00ab2859f5d7ae8fda7bd8e96f1bcda0srv.exe

Detected by UnHackMe:

DESKTOPLAYER.EXE
Default location: %PROGRAM FILES%\MICROSOFT\DESKTOPLAYER.EXE

Dropper information:
MD5: 00ab2859f5d7ae8fda7bd8e96f1bcda0
File size: 114176 bytes

Leave a Reply