EMAIL-BUSINESS.EMAIL.VERIFIER.V7.4.EXE – Trojan Banker

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

EMAIL-BUSINESS.EMAIL.VERIFIER.V7.4.EXE – Trojan Banker removal

FileMD5Virus Alias
EMAIL-BUSINESS.EMAIL.VERIFIER.V7.4.EXE db6ec5d78a22500c32b5e9678040af55 Trojan Banker
EMAIL-BUSINESS.EMAIL.VERIFIER.V7.4.EXE db6ec5d78a22500c32b5e9678040af55 Trojan Chifrax

EMAIL-BUSINESS.EMAIL.VERIFIER.V7.4.EXE size: 16381571 bytes
EMAIL-BUSINESS.EMAIL.VERIFIER.V7.4.EXE hash: DB6EC5D78A22500C32B5E9678040AF55

Created files:

%Program Files%\Aolex\Acfmz.exe
%Program Files%\Aolex\Atay\Jlenp.dll
%Program Files%\Aolex\Yeek.exe
%TEMP%\g83C\Email-Business.Email.Verifier.v7.4.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Aolex\Yeek.exe

Detected by UnHackMe:

EMAIL-BUSINESS.EMAIL.VERIFIER.V7.4.EXE
Default location: %TEMP%\G83C\EMAIL-BUSINESS.EMAIL.VERIFIER.V7.4.EXE

Dropper information:
MD5: 9ee84e0f9c5a617f51053a622afbebf8
File size: 18326563 bytes

Leave a Reply