OOTF.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

OOTF.EXE – Trojan Delf removal

FileMD5Virus Alias
OOTF.EXE 303B3317F1996740EE6CBF2FFF7AE955 Trojan Delf
OOTF.EXE 303B3317F1996740EE6CBF2FFF7AE955 Trojan Generic
OOTF.EXE 303B3317F1996740EE6CBF2FFF7AE955 Trojan Eldorado
OOTF.EXE 303B3317F1996740EE6CBF2FFF7AE955 Trojan Siggen
OOTF.EXE 303B3317F1996740EE6CBF2FFF7AE955 Trojan Agent

OOTF.EXE size: 862482 bytes
OOTF.EXE hash: 303B3317F1996740EE6CBF2FFF7AE955

Created files:

%Program Files%\Bkxur\Odge\Hcax.dll
%Program Files%\Bkxur\Ootf.exe
%Program Files%\Bkxur\Vaty.exe
%TEMP%\g812\StreamingStar.URL.Helper.v3.03.WinAll.Incl.Keygen-CRD.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Bkxur\Ootf.exe

Detected by UnHackMe:

OOTF.EXE
Default location: %PROGRAM FILES%\BKXUR\OOTF.EXE

Dropper information:
MD5: 9FE8A85771AC1EF3BF0CE4BACB9CBA2B
File size: 3032210 bytes

Leave a Reply