VIDEOREDO.TVSUITE.V3.1.5.564.EXE – Trojan Banker

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

VIDEOREDO.TVSUITE.V3.1.5.564.EXE – Trojan Banker removal

File MD5 Virus Alias
VIDEOREDO.TVSUITE.V3.1.5.564.EXE 7e048fa39bf5dd20862386e60da44a42 Trojan Banker
VIDEOREDO.TVSUITE.V3.1.5.564.EXE 7e048fa39bf5dd20862386e60da44a42 Trojan Chifrax

VIDEOREDO.TVSUITE.V3.1.5.564.EXE size: 12008237 bytes
VIDEOREDO.TVSUITE.V3.1.5.564.EXE hash: 7E048FA39BF5DD20862386E60DA44A42

Created files:

%Program Files%\Ttojq\Ocdt\Aoveo.dll
%Program Files%\Ttojq\Utcqb.exe
%Program Files%\Ttojq\Xfol.exe
%TEMP%\g8145\VideoReDo.TVSuite.v3.1.5.564.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Ttojq\Xfol.exe

Detected by UnHackMe:

VIDEOREDO.TVSUITE.V3.1.5.564.EXE
Default location: %TEMP%\G8145\VIDEOREDO.TVSUITE.V3.1.5.564.EXE

Dropper information:
MD5: f173ffbde810c002ec26dad6d3232ca3
File size: 13953236 bytes

Leave a Reply