RAIDENMAILD.V1.9.16.XP.VERSION-LZ0.EXE – Trojan Chifrax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

RAIDENMAILD.V1.9.16.XP.VERSION-LZ0.EXE – Trojan Chifrax removal

FileMD5Virus Alias
RAIDENMAILD.V1.9.16.XP.VERSION-LZ0.EXE 72b04f13490f1b12031c68d31aa6b164 Trojan Chifrax
RAIDENMAILD.V1.9.16.XP.VERSION-LZ0.EXE 72b04f13490f1b12031c68d31aa6b164 Backdoor RBot

RAIDENMAILD.V1.9.16.XP.VERSION-LZ0.EXE size: 12967890 bytes
RAIDENMAILD.V1.9.16.XP.VERSION-LZ0.EXE hash: 72B04F13490F1B12031C68D31AA6B164

Created files:

%Program Files%\Kesog\Iyla.exe
%Program Files%\Kesog\Oigk\Kubiz.dll
%Program Files%\Kesog\Olwa.exe
%TEMP%\g839\RaidenMAILD.v1.9.16.XP.Version-Lz0.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Kesog\Iyla.exe

Detected by UnHackMe:

RAIDENMAILD.V1.9.16.XP.VERSION-LZ0.EXE
Default location: %TEMP%\G839\RAIDENMAILD.V1.9.16.XP.VERSION-LZ0.EXE

Dropper information:
MD5: 750cbd1f38887dabd918ec854c216605
File size: 14912663 bytes

Leave a Reply