SUNISOFT.IRISSKIN.FOR.NET.WINFORMS.V3.50.EXE – Trojan Banker

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SUNISOFT.IRISSKIN.FOR.NET.WINFORMS.V3.50.EXE – Trojan Banker removal

File MD5 Virus Alias
SUNISOFT.IRISSKIN.FOR.NET.WINFORMS.V3.50.EXE 24db1f510bfe47048ecd6ec3bf0e186e Trojan Banker
SUNISOFT.IRISSKIN.FOR.NET.WINFORMS.V3.50.EXE 24db1f510bfe47048ecd6ec3bf0e186e Trojan Bad-Reputation
SUNISOFT.IRISSKIN.FOR.NET.WINFORMS.V3.50.EXE 24db1f510bfe47048ecd6ec3bf0e186e Trojan Agent

SUNISOFT.IRISSKIN.FOR.NET.WINFORMS.V3.50.EXE size: 6384577 bytes
SUNISOFT.IRISSKIN.FOR.NET.WINFORMS.V3.50.EXE hash: 24DB1F510BFE47048ECD6EC3BF0E186E

Created files:

%Program Files%\Iejf\Hecp\Dacbs.dll
%Program Files%\Iejf\Tugpk.exe
%Program Files%\Iejf\Umzvk.exe
%TEMP%\g88C\SuniSoft.IrisSkin.for.NET.Winforms.v3.50.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Iejf\Umzvk.exe

Detected by UnHackMe:

SUNISOFT.IRISSKIN.FOR.NET.WINFORMS.V3.50.EXE
Default location: %TEMP%\G88C\SUNISOFT.IRISSKIN.FOR.NET.WINFORMS.V3.50.EXE

Dropper information:
MD5: 76aecc9c88fe9f2a9b69550c00850d63
File size: 8329786 bytes

Leave a Reply