WINFTP.SERVER.V2.3.0.EXE – Trojan Chifrax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

WINFTP.SERVER.V2.3.0.EXE – Trojan Chifrax removal

FileMD5Virus Alias
WINFTP.SERVER.V2.3.0.EXE ca9fa2071c4751caf878fba6ab3ea241 Trojan Chifrax

WINFTP.SERVER.V2.3.0.EXE size: 2896369 bytes
WINFTP.SERVER.V2.3.0.EXE hash: CA9FA2071C4751CAF878FBA6AB3EA241

Created files:

%Program Files%\Lgemb\Ariij.exe
%Program Files%\Lgemb\Azeqi.exe
%Program Files%\Lgemb\Rsov\Wqza.dll
%TEMP%\g812\WinFTP.Server.v2.3.0.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Lgemb\Ariij.exe

Detected by UnHackMe:

WINFTP.SERVER.V2.3.0.EXE
Default location: %TEMP%\G812\WINFTP.SERVER.V2.3.0.EXE

Dropper information:
MD5: 778ab45b3f5393e0fc3262261aeaff54
File size: 4840962 bytes

Leave a Reply