LL8KLL8K.EXE – Trojan SuspiciousFile

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

LL8KLL8K.EXE – Trojan SuspiciousFile removal

FileMD5Virus Alias
LL8KLL8K.EXE ee6a584a57c2cab4ecb9cbb170336190 Trojan SuspiciousFile
LL8KLL8K.EXE ee6a584a57c2cab4ecb9cbb170336190 Trojan Generic
LL8KLL8K.EXE ee6a584a57c2cab4ecb9cbb170336190 Trojan Click
LL8KLL8K.EXE ee6a584a57c2cab4ecb9cbb170336190 Trojan Agent
LL8KLL8K.EXE ee6a584a57c2cab4ecb9cbb170336190 Trojan Banker

LL8KLL8K.EXE size: 4692069 bytes
LL8KLL8K.EXE hash: EE6A584A57C2CAB4ECB9CBB170336190

Created files:

%Program Files%\Xpakm\Cabb\Xajls.dll
%Program Files%\Xpakm\Iuqi.exe
%Program Files%\Xpakm\Wuok.exe
%TEMP%\g815\ll8kll8k.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\ALXO\Start: 02000000
HKLM\System\CurrentControlSet\Services\ALXO\Type: 10000000
HKLM\System\CurrentControlSet\Services\ALXO\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\ALXO\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\ALXO\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\ALXO\Group: TDI
HKLM\System\CurrentControlSet\Services\ALXO\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\ALXO\ImagePath: %Program Files%\Xpakm\Wuok.exe

Detected by UnHackMe:

LL8KLL8K.EXE
Default location: %TEMP%\G815\LL8KLL8K.EXE

Dropper information:
MD5: 0bba108e8634e1ba0c9c89e081581fe9
File size: 6658770 bytes

Leave a Reply