MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE – Trojan KeygenRiskware

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE – Trojan KeygenRiskware removal

FileMD5Virus Alias
MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE 1f8fd0fe300f35c0f3526fa48147f6aa Trojan KeygenRiskware
MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE 1f8fd0fe300f35c0f3526fa48147f6aa Trojan Generic
MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE 1f8fd0fe300f35c0f3526fa48147f6aa Trojan Chifrax
MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE 1f8fd0fe300f35c0f3526fa48147f6aa Trojan Genome
MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE 1f8fd0fe300f35c0f3526fa48147f6aa Trojan Agent

MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE size: 7891005 bytes
MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE hash: 1F8FD0FE300F35C0F3526FA48147F6AA

Created files:

%Program Files%\Ijfq\Ouept.exe
%Program Files%\Ijfq\Ultx\Jafs.dll
%Program Files%\Ijfq\Wpgar.exe
%TEMP%\g83D\MediaMonkey.Gold.v3.1.0.1256.Multilingual.Incl.Keymaker-CORE.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Ijfq\Wpgar.exe

Detected by UnHackMe:

MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE
Default location: %TEMP%\G83D\MEDIAMONKEY.GOLD.V3.1.0.1256.MULTILINGUAL.INCL.KEYMAKER-CORE.EXE

Dropper information:
MD5: a3afa234a622f0dec52ebc764955bf84
File size: 9836352 bytes

Leave a Reply