CHP.EXE – Trojan HideExec

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CHP.EXE – Trojan HideExec removal

FileMD5Virus Alias
CHP.EXE a6c90d52e51e95966ae1b2467cd192b9 Trojan HideExec
CHP.EXE a6c90d52e51e95966ae1b2467cd192b9 Trojan Bitcoin
CHP.EXE a6c90d52e51e95966ae1b2467cd192b9 Trojan Generic
CHP.EXE a6c90d52e51e95966ae1b2467cd192b9 Trojan CI
CHP.EXE a6c90d52e51e95966ae1b2467cd192b9 Trojan Agent

CHP.EXE size: 41984 bytes
CHP.EXE hash: A6C90D52E51E95966AE1B2467CD192B9

Created files:

%Program Files%\%appdata%\orac\chp.exe
%Program Files%\%appdata%\orac\diablo121016.cl
%Program Files%\%appdata%\orac\diakgcn121016.cl
%Program Files%\%appdata%\orac\libblkmaker-0.1-0.dll
%Program Files%\%appdata%\orac\libblkmaker_jansson-0.1-0.dll
%Program Files%\%appdata%\orac\libcurl-4.dll
%Program Files%\%appdata%\orac\libjansson-4.dll
%Program Files%\%appdata%\orac\libusb-1.0.dll
%Program Files%\%appdata%\orac\miner.php
%Program Files%\%appdata%\orac\pdcurses.dll
%Program Files%\%appdata%\orac\phatk121016.cl
%Program Files%\%appdata%\orac\poclbm121016.cl
%Program Files%\%appdata%\orac\pthreadGC2.dll
%Program Files%\%appdata%\orac\scrypt121016.cl
%Program Files%\%appdata%\orac\scvhost.exe
%Program Files%\%appdata%\orac\zlib1.dll

Detected by UnHackMe:

CHP.EXE
Default location: %PROGRAM FILES%\%APPDATA%\ORAC\CHP.EXE

Dropper information:
MD5: e4c9ea505db15faa470b8f364e8f3067
File size: 600383 bytes

Leave a Reply