ACTIVEAT.FILE.RECOVERY.V7.3.123.WINALL.CRACKED-CRD.EXE – Trojan BadReputation

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

ACTIVEAT.FILE.RECOVERY.V7.3.123.WINALL.CRACKED-CRD.EXE – Trojan BadReputation removal

FileMD5Virus Alias
ACTIVEAT.FILE.RECOVERY.V7.3.123.WINALL.CRACKED-CRD.EXE ff3a4f8f40811cbd6d1414c2ba114881 Trojan BadReputation
ACTIVEAT.FILE.RECOVERY.V7.3.123.WINALL.CRACKED-CRD.EXE ff3a4f8f40811cbd6d1414c2ba114881 Trojan SuspiciousFile
ACTIVEAT.FILE.RECOVERY.V7.3.123.WINALL.CRACKED-CRD.EXE ff3a4f8f40811cbd6d1414c2ba114881 Trojan Chifrax

ACTIVEAT.FILE.RECOVERY.V7.3.123.WINALL.CRACKED-CRD.EXE size: 4443680 bytes
ACTIVEAT.FILE.RECOVERY.V7.3.123.WINALL.CRACKED-CRD.EXE hash: FF3A4F8F40811CBD6D1414C2BA114881

Created files:

%Program Files%\Ruve\Aeyrv\Moid.dll
%Program Files%\Ruve\Idol.exe
%Program Files%\Ruve\Uetir.exe
%TEMP%\g8A9\ActiveAT.File.Recovery.v7.3.123.WinAll.Cracked-CRD.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Ruve\Idol.exe

Detected by UnHackMe:

ACTIVEAT.FILE.RECOVERY.V7.3.123.WINALL.CRACKED-CRD.EXE
Default location: %TEMP%\G8A9\ACTIVEAT.FILE.RECOVERY.V7.3.123.WINALL.CRACKED-CRD.EXE

Dropper information:
MD5: b7be332370a25f79cf4e718d48b4aa0e
File size: 6388294 bytes

Leave a Reply