DWG.TO.PDF.CONVERTER.V3.0-BEAN.EXE – Trojan Chifrax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DWG.TO.PDF.CONVERTER.V3.0-BEAN.EXE – Trojan Chifrax removal

FileMD5Virus Alias
DWG.TO.PDF.CONVERTER.V3.0-BEAN.EXE 24ec5ebea6889c27b63e19a246f19829 Trojan Chifrax

DWG.TO.PDF.CONVERTER.V3.0-BEAN.EXE size: 6263738 bytes
DWG.TO.PDF.CONVERTER.V3.0-BEAN.EXE hash: 24EC5EBEA6889C27B63E19A246F19829

Created files:

%Program Files%\Fdai\Adzpm.exe
%Program Files%\Fdai\Mtku.exe
%Program Files%\Fdai\Obdw\Ffku.dll
%TEMP%\g810\DWG.to.PDF.Converter.v3.0-BEAN.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Fdai\Adzpm.exe

Detected by UnHackMe:

DWG.TO.PDF.CONVERTER.V3.0-BEAN.EXE
Default location: %TEMP%\G810\DWG.TO.PDF.CONVERTER.V3.0-BEAN.EXE

Dropper information:
MD5: 1cb213a6ed3274f84b2200a60f98f71f
File size: 8208241 bytes

Leave a Reply