I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
IBWIM.EXE – Trojan Delf removal
File | MD5 | Virus Alias |
---|---|---|
IBWIM.EXE | 1f5f337c5f25e82216c80a5ced62cd93 | Trojan Delf |
IBWIM.EXE | 1f5f337c5f25e82216c80a5ced62cd93 | Trojan Generic |
IBWIM.EXE | 1f5f337c5f25e82216c80a5ced62cd93 | Trojan Eldorado |
IBWIM.EXE | 1f5f337c5f25e82216c80a5ced62cd93 | Trojan Siggen |
IBWIM.EXE | 1f5f337c5f25e82216c80a5ced62cd93 | Trojan Agent |
IBWIM.EXE size: 668059 bytes
IBWIM.EXE hash: 1F5F337C5F25E82216C80A5CED62CD93
Created files:
%Program Files%\Ddalm\Fcgu\Leqx.dll
%Program Files%\Ddalm\Ibwim.exe
%Program Files%\Ddalm\Tiowj.exe
%TEMP%\g843\Runtime.GetDataBack.for.NTFS.v3.69.Incl.Keygen-BRD.exe
Autostart registry keys:
HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Ddalm\Tiowj.exe
Detected by UnHackMe:
IBWIM.EXE
Default location: %PROGRAM FILES%\DDALM\IBWIM.EXE
Dropper information:
MD5: 62c587de243b5d14582cdb3e4c477808
File size: 4911334 bytes