DJ.JAVA.DECOMPILER.V3.11.11.95-INVISIBLE.EXE – Trojan Chifrax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DJ.JAVA.DECOMPILER.V3.11.11.95-INVISIBLE.EXE – Trojan Chifrax removal

FileMD5Virus Alias
DJ.JAVA.DECOMPILER.V3.11.11.95-INVISIBLE.EXE 201da58db136018a932b80019f9f8c76 Trojan Chifrax

DJ.JAVA.DECOMPILER.V3.11.11.95-INVISIBLE.EXE size: 6762012 bytes
DJ.JAVA.DECOMPILER.V3.11.11.95-INVISIBLE.EXE hash: 201DA58DB136018A932B80019F9F8C76

Created files:

%Program Files%\Gaok\Dirue.exe
%Program Files%\Gaok\Fxopp\Umpo.dll
%Program Files%\Gaok\Tuhr.exe
%TEMP%\g88E\DJ.Java.Decompiler.v3.11.11.95-iNViSiBLE.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Gaok\Tuhr.exe

Detected by UnHackMe:

DJ.JAVA.DECOMPILER.V3.11.11.95-INVISIBLE.EXE
Default location: %TEMP%\G88E\DJ.JAVA.DECOMPILER.V3.11.11.95-INVISIBLE.EXE

Dropper information:
MD5: 6ae55ce99ec0a2e31cfc5730ec0c3901
File size: 8768466 bytes

Leave a Reply