SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE – Backdoor Maximus

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE – Backdoor Maximus removal

FileMD5Virus Alias
SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE 80025ff8b9d8c603695bf17717294dbb Backdoor Maximus
SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE 80025ff8b9d8c603695bf17717294dbb Trojan SuspiciousFile
SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE 80025ff8b9d8c603695bf17717294dbb Trojan Generic
SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE 80025ff8b9d8c603695bf17717294dbb Trojan Eldorado
SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE 80025ff8b9d8c603695bf17717294dbb Trojan Downloader
SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE 80025ff8b9d8c603695bf17717294dbb Trojan DNAScan

SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE size: 229162 bytes
SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE hash: 80025FF8B9D8C603695BF17717294DBB

Created files:

%Program Files%\Cwlu\Eoxen\Tirj.dll
%Program Files%\Cwlu\Goyw.exe
%Program Files%\Cwlu\Urkem.exe
%TEMP%\g810\SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-Keygen.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Cwlu\Urkem.exe

Detected by UnHackMe:

SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE
Default location: %TEMP%\G810\SITNI_SATI_DREAMSCAPE_V2.5D_FOR_3DS_MAX_2009_64BIT-XFORCE-KEYGEN.EXE

Dropper information:
MD5: 207dad49d4bf7ecbdfa4c0dac44bcddd
File size: 2174340 bytes

Leave a Reply