AXPWCJ.EXE – Backdoor Xyligan

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

AXPWCJ.EXE – Backdoor Xyligan removal

FileMD5Virus Alias
AXPWCJ.EXE aa96876eb58f5eaa52ef4bcc414fcbe7 Backdoor Xyligan
AXPWCJ.EXE aa96876eb58f5eaa52ef4bcc414fcbe7 Trojan PcClient
AXPWCJ.EXE aa96876eb58f5eaa52ef4bcc414fcbe7 Trojan Eldorado
AXPWCJ.EXE aa96876eb58f5eaa52ef4bcc414fcbe7 Backdoor PcClien
AXPWCJ.EXE aa96876eb58f5eaa52ef4bcc414fcbe7 Backdoor Nitol
AXPWCJ.EXE aa96876eb58f5eaa52ef4bcc414fcbe7 Trojan Agent

AXPWCJ.EXE size: 58368 bytes
AXPWCJ.EXE hash: AA96876EB58F5EAA52EF4BCC414FCBE7

Created files:

%SysDir%\axpwcj.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\rcmdsvc\Type: 10000000
HKLM\System\CurrentControlSet\Services\rcmdsvc\Start: 02000000
HKLM\System\CurrentControlSet\Services\rcmdsvc\DisplayName: Remote Command Service
HKLM\System\CurrentControlSet\Services\rcmdsvc\ImagePath: %WinDir%\System32\axpwcj.exe
HKLM\System\CurrentControlSet\Services\rcmdsvc\Description: Windows Resource Kit

Detected by UnHackMe:

AXPWCJ.EXE
Default location: %SYSDIR%\AXPWCJ.EXE

Dropper information:
MD5: aa96876eb58f5eaa52ef4bcc414fcbe7
File size: 58368 bytes

Leave a Reply