Solved! Use CZZE.EXE (Trojan Delf) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

CZZE.EXE – Trojan Delf removal

File MD5 Virus Alias
CZZE.EXE 2808ea19a1cbf174bc3ce0ae6091f993 Trojan Delf
CZZE.EXE 2808ea19a1cbf174bc3ce0ae6091f993 Trojan Generic
CZZE.EXE 2808ea19a1cbf174bc3ce0ae6091f993 Trojan Eldorado
CZZE.EXE 2808ea19a1cbf174bc3ce0ae6091f993 Trojan Graftor
CZZE.EXE 2808ea19a1cbf174bc3ce0ae6091f993 Trojan Siggen
CZZE.EXE 2808ea19a1cbf174bc3ce0ae6091f993 Trojan Agent

CZZE.EXE size: 862041 bytes
CZZE.EXE hash: 2808EA19A1CBF174BC3CE0AE6091F993

Created files:

%Program Files%\Mejr\Czze.exe
%Program Files%\Mejr\Fuvqp\Imvia.dll
%Program Files%\Mejr\Wzays.exe
%Temp%\g823\Videomach.v5.5.1.Professional.Cracked-F4CG.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Mejr\Czze.exe

Detected by UnHackMe:

CZZE.EXE
Default location: %PROGRAM FILES%\MEJR\CZZE.EXE

Dropper information:
MD5: 707d3534161c156a6075a49c0d7a0b7e
File size: 6566199 bytes

Leave a Reply