BOVXDYYO.EXE – Trojan-Ransom Winlock

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

BOVXDYYO.EXE – Trojan-Ransom Winlock removal

File MD5 Virus Alias
BOVXDYYO.EXE 864f92f2cefd86409a4e40dd173a2ab0 Trojan-Ransom Winlock
BOVXDYYO.EXE 864f92f2cefd86409a4e40dd173a2ab0 Trojan Hlux
BOVXDYYO.EXE 864f92f2cefd86409a4e40dd173a2ab0 Trojan SuspiciousFile
BOVXDYYO.EXE 864f92f2cefd86409a4e40dd173a2ab0 Trojan Artemis
BOVXDYYO.EXE 864f92f2cefd86409a4e40dd173a2ab0 Trojan Generic
BOVXDYYO.EXE 864f92f2cefd86409a4e40dd173a2ab0 Trojan DNAScan

BOVXDYYO.EXE size: 254966 bytes
BOVXDYYO.EXE hash: 864F92F2CEFD86409A4E40DD173A2AB0

Created files:

%Program Files%\Dirty\DirtyDecrypt.exe
%Program Files%\MSN Gaming Zone\tNQqTPKD.exe
%AppData%\Dirty\DirtyDecrypt.exe
%Local AppData%\Dirty\DirtyDecrypt.exe
%Local AppData%\Microsoft\BovXdYyO.exe
%SysDir%\config\systemprofile\Start Menu\Programs\Startup\sdmmVYnN.exe
%TEMP%\OLCjeUbW.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: %WinDir%\System32\userinit.exe,,%Program Files%\MSN Gaming Zone\tNQqTPKD.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\AkjsDDLS: %WinDir%\System32\config\Systemprofile\Local Settings\Application Data\Microsoft\BovXdYyO.exe

Detected by UnHackMe:

BOVXDYYO.EXE
Default location: %LOCAL APPDATA%\MICROSOFT\BOVXDYYO.EXE

Dropper information:
MD5: 864f92f2cefd86409a4e40dd173a2ab0
File size: 254966 bytes

Leave a Reply