RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE – Trojan Artemis removal

FileMD5Virus Alias
RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE ffc945c24385ed6e3d78d1b646d34d5a Trojan Artemis
RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE ffc945c24385ed6e3d78d1b646d34d5a Trojan KeygenRiskware
RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE ffc945c24385ed6e3d78d1b646d34d5a Trojan PAK_Generic
RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE ffc945c24385ed6e3d78d1b646d34d5a Trojan Chifrax
RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE ffc945c24385ed6e3d78d1b646d34d5a Trojan Banker

RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE size: 2966034 bytes
RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE hash: FFC945C24385ED6E3D78D1B646D34D5A

Created files:

%Program Files%\Ddalm\Fcgu\Leqx.dll
%Program Files%\Ddalm\Ibwim.exe
%Program Files%\Ddalm\Tiowj.exe
%TEMP%\g843\Runtime.GetDataBack.for.NTFS.v3.69.Incl.Keygen-BRD.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Ddalm\Tiowj.exe

Detected by UnHackMe:

RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE
Default location: %TEMP%\G843\RUNTIME.GETDATABACK.FOR.NTFS.V3.69.INCL.KEYGEN-BRD.EXE

Dropper information:
MD5: 62c587de243b5d14582cdb3e4c477808
File size: 4911334 bytes

Leave a Reply