SMARTFTP.V3.0.1019.8.EXE – Trojan Banker

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SMARTFTP.V3.0.1019.8.EXE – Trojan Banker removal

File MD5 Virus Alias
SMARTFTP.V3.0.1019.8.EXE 3b2506a417e6cdf024891865b7d8dfe5 Trojan Banker
SMARTFTP.V3.0.1019.8.EXE 3b2506a417e6cdf024891865b7d8dfe5 Trojan Chifrax

SMARTFTP.V3.0.1019.8.EXE size: 7778891 bytes
SMARTFTP.V3.0.1019.8.EXE hash: 3B2506A417E6CDF024891865B7D8DFE5

Created files:

%Program Files%\Ilfx\Fyzes.exe
%Program Files%\Ilfx\Teidj.exe
%Program Files%\Ilfx\Xdkau\Msqi.dll
%TEMP%\g860\SmartFTP.v3.0.1019.8.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Ilfx\Teidj.exe

Detected by UnHackMe:

SMARTFTP.V3.0.1019.8.EXE
Default location: %TEMP%\G860\SMARTFTP.V3.0.1019.8.EXE

Dropper information:
MD5: b43e61377b720de30474f4198bb154b2
File size: 9723933 bytes

Leave a Reply