dfgx.exe

OLX

The application dfgx.exe by OLX has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PlayCenter’.
Publisher:
OLX  (signed and verified)

Version:
18.0.0.0

MD5:
f457c4ae8c5cb2255f451cb2ebacc21f

SHA-1:
9080f61dd82feeedba0e1f8895c07e9ebb576e05

SHA-256:
3f4254bc5ffc3fdc5020a3219e8286afae92ef34876d861d36db7f67b7948a4c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/6/2024 1:50:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OLX (M)
16.3.21.7

File size:
16.7 MB (17,488,824 bytes)

Product version:
18.0.0.0

Original file name:
Vix.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\dfgx.exe

Digital Signature
Signed by:

Authority:
OLX

Valid from:
10/6/2015 8:18:40 AM

Valid to:
10/6/2016 8:18:40 AM

Subject:
CN=www.olx.co, O=OLX, L=Sao Paulo, S=SP, C=AT

Issuer:
CN=www.olx.co, O=OLX, L=Sao Paulo, S=SP, C=AT

Serial number:
008F8AF4F4CDA30E10

File PE Metadata
Compilation timestamp:
10/9/2015 11:56:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:yrM6O2N5KPD0WWnWWWWWWWWWWWUx9EfWFAWWM2WPW+WWLWWxWDWHqJN7nfd/WaW3:y

Entry address:
0x10AE67E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16.7 MB (17,483,776 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PlayCenter

Command:
C:\users\{user}\appdata\roaming\dfgx.exe


Remove dfgx.exe - Powered by Reason Core Security