I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
PHOTOTUNE.TESTSTRIP.PROOFER.PRO.V1.1.FOR.PHOTOSHOP-SCOTCH.EXE – Trojan Agent removal
File | MD5 | Virus Alias |
---|---|---|
PHOTOTUNE.TESTSTRIP.PROOFER.PRO.V1.1.FOR.PHOTOSHOP-SCOTCH.EXE | 654342d5fc5b5bbf39f6a1ec8bcb90ca | Trojan Agent |
PHOTOTUNE.TESTSTRIP.PROOFER.PRO.V1.1.FOR.PHOTOSHOP-SCOTCH.EXE | 654342d5fc5b5bbf39f6a1ec8bcb90ca | Trojan Chifrax |
PHOTOTUNE.TESTSTRIP.PROOFER.PRO.V1.1.FOR.PHOTOSHOP-SCOTCH.EXE size: 197418 bytes
PHOTOTUNE.TESTSTRIP.PROOFER.PRO.V1.1.FOR.PHOTOSHOP-SCOTCH.EXE hash: 654342D5FC5B5BBF39F6A1EC8BCB90CA
Created files:
%Program Files%\Weoj\Iwntx.exe
%Program Files%\Weoj\Podf.exe
%Program Files%\Weoj\Secns\Nbaa.dll
%TEMP%\g8B6\PhotoTune.TestStrip.Proofer.Pro.v1.1.for.Photoshop-SCOTCH.exe
Autostart registry keys:
HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Weoj\Iwntx.exe
Detected by UnHackMe:
PHOTOTUNE.TESTSTRIP.PROOFER.PRO.V1.1.FOR.PHOTOSHOP-SCOTCH.EXE
Default location: %TEMP%\G8B6\PHOTOTUNE.TESTSTRIP.PROOFER.PRO.V1.1.FOR.PHOTOSHOP-SCOTCH.EXE
Dropper information:
MD5: c92b57b9f6767417fd308d66b71274a8
File size: 2142062 bytes