TIRJ.DLL – Backdoor Hupigon

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

TIRJ.DLL – Backdoor Hupigon removal

File MD5 Virus Alias
TIRJ.DLL 2eceeb1c0bc36e846c4a46a5fe4d8c7a Backdoor Hupigon
TIRJ.DLL 2eceeb1c0bc36e846c4a46a5fe4d8c7a Trojan Generic
TIRJ.DLL 2eceeb1c0bc36e846c4a46a5fe4d8c7a Trojan Eldorado
TIRJ.DLL 2eceeb1c0bc36e846c4a46a5fe4d8c7a Backdoor Pigeon
TIRJ.DLL 2eceeb1c0bc36e846c4a46a5fe4d8c7a Trojan Agent
TIRJ.DLL 2eceeb1c0bc36e846c4a46a5fe4d8c7a Trojan Delf

TIRJ.DLL size: 873200 bytes
TIRJ.DLL hash: 2ECEEB1C0BC36E846C4A46A5FE4D8C7A

Created files:

%Program Files%\Cwlu\Eoxen\Tirj.dll
%Program Files%\Cwlu\Goyw.exe
%Program Files%\Cwlu\Urkem.exe
%TEMP%\g810\SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-Keygen.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Cwlu\Urkem.exe

Detected by UnHackMe:

TIRJ.DLL
Default location: %PROGRAM FILES%\CWLU\EOXEN\TIRJ.DLL

Dropper information:
MD5: 207dad49d4bf7ecbdfa4c0dac44bcddd
File size: 2174340 bytes

Leave a Reply