IHXIB.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

IHXIB.EXE – Trojan Delf removal

FileMD5Virus Alias
IHXIB.EXE 2acba25391c09d3a2c026c1b32c26253 Trojan Delf
IHXIB.EXE 2acba25391c09d3a2c026c1b32c26253 Trojan Generic
IHXIB.EXE 2acba25391c09d3a2c026c1b32c26253 Trojan Eldorado
IHXIB.EXE 2acba25391c09d3a2c026c1b32c26253 Trojan Siggen
IHXIB.EXE 2acba25391c09d3a2c026c1b32c26253 Trojan Agent

IHXIB.EXE size: 862250 bytes
IHXIB.EXE hash: 2ACBA25391C09D3A2C026C1B32C26253

Created files:

%Program Files%\Urtr\Aalz.exe
%Program Files%\Urtr\Ihxib.exe
%Program Files%\Urtr\Ipan\Vnikw.dll
%TEMP%\g8139\Kaskade.v1.0.9.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Urtr\Ihxib.exe

Detected by UnHackMe:

IHXIB.EXE
Default location: %PROGRAM FILES%\URTR\IHXIB.EXE

Dropper information:
MD5: dc093c7b1ffdb6e1a8ba65c310cb8966
File size: 3965786 bytes

Leave a Reply