dfgx.exe

OLX

The executable dfgx.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PlayCenter’.
Publisher:
OLX  (signed and verified)

Version:
6.0.0.0

MD5:
a9ebd0b2d7be1a5d0a76c8892ba95baa

SHA-1:
04d13d42902255df7edfb135da5574e1c2e9a5f7

SHA-256:
e57f0c29c694071d009df3787322f51930cd91e3534e4c519033ae3cc956dac2

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/6/2024 2:15:45 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.10.19.12

File size:
16.1 MB (16,847,800 bytes)

Product version:
6.0.0.0

Original file name:
BODPCPPQOXPQX.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\dfgx.exe

Digital Signature
Signed by:

Authority:
OLX

Valid from:
10/4/2015 11:37:02 AM

Valid to:
10/4/2016 11:37:02 AM

Subject:
CN=www.olx.pt, O=OLX, L=Lisboa, S=Lisboa, C=PN

Issuer:
CN=www.olx.pt, O=OLX, L=Lisboa, S=Lisboa, C=PN

Serial number:
00D2E418114F6B0AC6

File PE Metadata
Compilation timestamp:
10/4/2015 7:52:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:MQbb9I/YoEJSSjlUPkOGsavMN4XPiijm+7QZZjZnDZ+x1GBNmf0ckPOX6DPnGhf5:M4

Entry address:
0x1011CCE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16.1 MB (16,842,240 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PlayCenter

Command:
C:\users\{user}\appdata\roaming\dfgx.exe


Remove dfgx.exe - Powered by Reason Core Security