CHCFG.EXE – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CHCFG.EXE – Trojan Agent removal

FileMD5Virus Alias
CHCFG.EXE eb16d96e39e3bc82edcad6df3ca7e94b Trojan Agent

CHCFG.EXE size: 76392 bytes
CHCFG.EXE hash: EB16D96E39E3BC82EDCAD6DF3CA7E94B

Created files:

%TEMP%\RarSFX0\ChCfg.exe
%TEMP%\RarSFX0\data1.cab
%TEMP%\RarSFX0\data1.hdr
%TEMP%\RarSFX0\data2.cab
%TEMP%\RarSFX0\engine32.cab
%TEMP%\RarSFX0\layout.bin
%TEMP%\RarSFX0\RtlExUpd.dll
%TEMP%\RarSFX0\setup.ibt
%TEMP%\RarSFX0\setup.inx
%TEMP%\RarSFX0\setup.isn
%TEMP%\RarSFX0\setup.iss
%TEMP%\RarSFX0\USetup.iss
%TEMP%\RarSFX0\Vista\AcpiServiceVnA.dll
%TEMP%\RarSFX0\Vista\AERTACap.dll
%TEMP%\RarSFX0\Vista\AERTARen.dll
%TEMP%\RarSFX0\Vista\AERTSrv.exe
%TEMP%\RarSFX0\Vista\BlackBlueSkinImages.dll
%TEMP%\RarSFX0\Vista\BlackSkinImages.dll
%TEMP%\RarSFX0\Vista\CONEQMSAPO.dll
%TEMP%\RarSFX0\Vista\CONEQMSAPOGUILibrary.dll
%TEMP%\RarSFX0\Vista\CreateRtkToastLnk.exe
%TEMP%\RarSFX0\Vista\DarkSkinImages.dll
%TEMP%\RarSFX0\Vista\DTSAudioService.exe
%TEMP%\RarSFX0\Vista\DTSBassEnhancementDLL.dll
%TEMP%\RarSFX0\Vista\DTSBoostDLL.dll
%TEMP%\RarSFX0\Vista\DTSGainCompensatorDLL.dll
%TEMP%\RarSFX0\Vista\DTSGFXAPO.dll
%TEMP%\RarSFX0\Vista\DTSGFXAPONS.dll
%TEMP%\RarSFX0\Vista\DTSLFXAPO.dll
%TEMP%\RarSFX0\Vista\DTSLimiterDLL.dll
%TEMP%\RarSFX0\Vista\DTSNeoPCDLL.dll
%TEMP%\RarSFX0\Vista\DTSS2HeadphoneDLL.dll
%TEMP%\RarSFX0\Vista\DTSS2SpeakerDLL.dll
%TEMP%\RarSFX0\Vista\DTSSymmetryDLL.dll
%TEMP%\RarSFX0\Vista\DTSU2PAuSrv32.exe
%TEMP%\RarSFX0\Vista\DTSU2PGFX32.dll
%TEMP%\RarSFX0\Vista\DTSU2PLFX32.dll
%TEMP%\RarSFX0\Vista\DTSU2PREC32.dll
%TEMP%\RarSFX0\Vista\DTSVoiceClarityDLL.dll
%TEMP%\RarSFX0\Vista\FMAPO.dll
%TEMP%\RarSFX0\Vista\FMAPP.exe
%TEMP%\RarSFX0\Vista\GrayJadeSkinImages.dll

Detected by UnHackMe:

CHCFG.EXE
Default location: %TEMP%\RARSFX0\CHCFG.EXE

Dropper information:
MD5: 4cc83d802b022492eecbe476bd4efe9c
File size: 166064048 bytes

Leave a Reply