OACFINS.EXE – Trojan Graftor

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

OACFINS.EXE – Trojan Graftor removal

FileMD5Virus Alias
OACFINS.EXE 0578b9305cc8612a3db2324148da75ac Trojan Graftor
OACFINS.EXE 0578b9305cc8612a3db2324148da75ac Trojan Artemis
OACFINS.EXE 0578b9305cc8612a3db2324148da75ac Trojan XPACK
OACFINS.EXE 0578b9305cc8612a3db2324148da75ac Trojan Eldorado
OACFINS.EXE 0578b9305cc8612a3db2324148da75ac Trojan CI
OACFINS.EXE 0578b9305cc8612a3db2324148da75ac Trojan Agent

OACFINS.EXE size: 202752 bytes
OACFINS.EXE hash: 0578B9305CC8612A3DB2324148DA75AC

Created files:

%Program Files%\Rukoyp aewiw\Oacfins.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Cgmuue gaskka\ConnectGroup: 3306
HKLM\System\CurrentControlSet\Services\Cgmuue gaskka\MarkTime: 2013-02-21 05:01
HKLM\System\CurrentControlSet\Services\Cgmuue gaskka\Type: 10010000
HKLM\System\CurrentControlSet\Services\Cgmuue gaskka\Start: 02000000
HKLM\System\CurrentControlSet\Services\Cgmuue gaskka\DisplayName: Sswumo oceaeweo
HKLM\System\CurrentControlSet\Services\Cgmuue gaskka\ImagePath: %Program Files%\Rukoyp aewiw\Oacfins.exe
HKLM\System\CurrentControlSet\Services\Rukqpm bpaeeuex\ReleiceName: Cgmuue gaskka

Detected by UnHackMe:

OACFINS.EXE
Default location: %PROGRAM FILES%\RUKOYP AEWIW\OACFINS.EXE

Dropper information:
MD5: 0578b9305cc8612a3db2324148da75ac
File size: 202752 bytes

Leave a Reply