Trojan Delf – 802d699ce7b9fe51892526165f5d7233

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Delf
Also known as: Trojan FakeAV, Trojan Agent
SHA256: fab9efc66bacef44cd7e7886e2e6d3df65fb30876c4bceec2cb7e19ca68f370e
SHA1: 46053c78956fe7fc9b43ba2ff076c636186e50ce
MD5: 802d699ce7b9fe51892526165f5d7233
File size: 6177442 bytes

Created files:

%Program Files%\Ozir\Asayn.exe – Trojan Delf
%Program Files%\Ozir\jy.ini – Trojan Delf
%Program Files%\Ozir\Lurb\Gtalw.dll – Trojan Delf
%Program Files%\Ozir\Uumx.exe – Trojan Delf
%Temp%\g81B\setup.ini – Trojan Delf
%Temp%\g81B\Windows7.PDF.exe – Trojan Delf

Trojan Delf created autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Ozir\Asayn.exe

Leave a Reply