COFFEECUP.GIF.ANIMATOR.V7.6.EXE – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

COFFEECUP.GIF.ANIMATOR.V7.6.EXE – Trojan Agent removal

FileMD5Virus Alias
COFFEECUP.GIF.ANIMATOR.V7.6.EXE c6481a3a31a1a62d816635f30b0a510d Trojan Agent

COFFEECUP.GIF.ANIMATOR.V7.6.EXE size: 2494526 bytes
COFFEECUP.GIF.ANIMATOR.V7.6.EXE hash: C6481A3A31A1A62D816635F30B0A510D

Created files:

%Program Files%\Egab\Anim.exe
%Program Files%\Egab\Ejpi\Ctzu.dll
%Program Files%\Egab\Emqzl.exe
%TEMP%\g821\CoffeeCup.GIF.Animator.v7.6.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Egab\Emqzl.exe

Detected by UnHackMe:

COFFEECUP.GIF.ANIMATOR.V7.6.EXE
Default location: %TEMP%\G821\COFFEECUP.GIF.ANIMATOR.V7.6.EXE

Dropper information:
MD5: 24c0ef70541194be432be0a612b2a46d
File size: 4439259 bytes

Leave a Reply