Solved! Use WZAYS.EXE (Trojan Delf) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

WZAYS.EXE – Trojan Delf removal

File MD5 Virus Alias
WZAYS.EXE 44d8cee334abfcdb439f6d9cb13ccc62 Trojan Delf
WZAYS.EXE 44d8cee334abfcdb439f6d9cb13ccc62 Trojan Generic
WZAYS.EXE 44d8cee334abfcdb439f6d9cb13ccc62 Trojan Eldorado
WZAYS.EXE 44d8cee334abfcdb439f6d9cb13ccc62 Trojan Graftor
WZAYS.EXE 44d8cee334abfcdb439f6d9cb13ccc62 Trojan Siggen

WZAYS.EXE size: 667989 bytes
WZAYS.EXE hash: 44D8CEE334ABFCDB439F6D9CB13CCC62

Created files:

%Program Files%\Mejr\Czze.exe
%Program Files%\Mejr\Fuvqp\Imvia.dll
%Program Files%\Mejr\Wzays.exe
%Temp%\g823\Videomach.v5.5.1.Professional.Cracked-F4CG.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Mejr\Czze.exe

Detected by UnHackMe:

WZAYS.EXE
Default location: %PROGRAM FILES%\MEJR\WZAYS.EXE

Dropper information:
MD5: 707d3534161c156a6075a49c0d7a0b7e
File size: 6566199 bytes

Leave a Reply