CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE – Trojan Artemis

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE – Trojan Artemis removal

FileMD5Virus Alias
CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE 97d38e24fde27da40a8040def40951fc Trojan Artemis
CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE 97d38e24fde27da40a8040def40951fc Trojan Generic
CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE 97d38e24fde27da40a8040def40951fc Trojan Xema
CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE 97d38e24fde27da40a8040def40951fc Trojan Chifrax
CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE 97d38e24fde27da40a8040def40951fc Trojan CI
CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE 97d38e24fde27da40a8040def40951fc Trojan Agent

CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE size: 165917 bytes
CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE hash: 97D38E24FDE27DA40A8040DEF40951FC

Created files:

%Program Files%\Isckz\Ekob.exe
%Program Files%\Isckz\Pxhau.exe
%Program Files%\Isckz\Soswo\Qsay.dll
%TEMP%\g81D\Chock-A-Block.v1.0.5.WinALL-CHiCNCREAM.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Isckz\Ekob.exe

Detected by UnHackMe:

CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE
Default location: %TEMP%\G81D\CHOCK-A-BLOCK.V1.0.5.WINALL-CHICNCREAM.EXE

Dropper information:
MD5: 1f85ab989685228c115dfcb113274a77
File size: 2110722 bytes

Leave a Reply