PHOTOSCORE.WINALL.V5.5.1.RETAIL-IND.EXE – Trojan Banker

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

PHOTOSCORE.WINALL.V5.5.1.RETAIL-IND.EXE – Trojan Banker removal

File MD5 Virus Alias
PHOTOSCORE.WINALL.V5.5.1.RETAIL-IND.EXE b455c389c244fc395b4784e4c333f1eb Trojan Banker
PHOTOSCORE.WINALL.V5.5.1.RETAIL-IND.EXE b455c389c244fc395b4784e4c333f1eb Trojan Agent

PHOTOSCORE.WINALL.V5.5.1.RETAIL-IND.EXE size: 21916451 bytes
PHOTOSCORE.WINALL.V5.5.1.RETAIL-IND.EXE hash: B455C389C244FC395B4784E4C333F1EB

Created files:

%Program Files%\Qjoid\Ttanj.exe
%Program Files%\Qjoid\Uxbi.exe
%Program Files%\Qjoid\Ylen\Rade.dll
%TEMP%\g8CC\Photoscore.WinALL.v5.5.1.RETAIL-iND.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Qjoid\Ttanj.exe

Detected by UnHackMe:

PHOTOSCORE.WINALL.V5.5.1.RETAIL-IND.EXE
Default location: %TEMP%\G8CC\PHOTOSCORE.WINALL.V5.5.1.RETAIL-IND.EXE

Dropper information:
MD5: e6eb1bc73058ed6579191ab013e7764e
File size: 23861664 bytes

Leave a Reply