Threat Database Trojans Trojan.Win32.Chifrax.a

Trojan.Win32.Chifrax.a

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 232
First Seen: August 15, 2011
Last Seen: May 21, 2021
OS(es) Affected: Windows

Trojan.Win32.Chifrax.a is a malicious Trojan infection that stealthily installs on a targeted user's PC without his/her knowledge. Trojan.Win32.Chifrax.a is created to attach and harm the data and files on the infected computer, which causes the improper running of the PC or failure to access the computer system. Once the computer is corrupted by Trojan.Win32.Chifrax.a, hackers can access it remotely and execute malicious activities. Trojan.Win32.Chifrax.a can steal and transmit your confidential data to remote servers. You need to delete Trojan.Win32.Chifrax.a from your computer instantly once you detect it to protect your PC.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
McAfee-GW-Edition Heuristic.LooksLike.Win32.Suspicious.N!83
TrendMicro TROJ_SPNR.0CCR12
Sophos Mal/Chifrax-A
eSafe Win32.TRCrypt.XPACK
K7AntiVirus Trojan
Sunbelt Activity Monitor (fs)
eSafe Win32.Spyware.ActMon
Symantec Spyware.ActMon
CAT-QuickHeal (Suspicious) - DNAScan
AVG Generic21.ARXH
AntiVir Adware/Agent.411136
BitDefender Adware.Generic.167851
Avast Win32:Adware-gen [Adw]
NOD32 probably unknown NewHeur_PE
McAfee Artemis!CEDFF8719E05

SpyHunter Detects & Remove Trojan.Win32.Chifrax.a

File System Details

Trojan.Win32.Chifrax.a may create the following file(s):
# File Name MD5 Detections
1. limbo.exe ad59c75020404a58c9c1d5cd9a343505 141
2. svchost.exe 752d8243ffe4b40c0b319c3230ee9d8c 3
3. DFServerService.exe 8e315f6c8d9959a1251a72fb19659e95 2
4. swsys.exe a43e3a45731e578c8e238c391c4b1007 1
5. Terraria.exe a075d150dd4447baa7cdd2f969d08b08 1
6. DivXCodec_AF.exe cedff8719e05eb8fde40d984e331de9a 1
7. lpad132.dll
8. lpad32.dll
9. cas.bat
10. lowapldl.dll
11. justing.ocx
12. web.lnk
13. exp1orer.lnk
14. magiciso.lnk
15. file.exe 595a43d329a70e107b940149aac5b1ee 0
16. file.exe 7b2a95ffc74340bcc7d4df554cb6a89d 0
17. file.exe 634f4e693944a5b55f8ecdd1586d5d6a 0
18. file.exe 56a5d5eb9adbdd6f7d61e1775e19de5b 0

Registry Details

Trojan.Win32.Chifrax.a may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Misosh.MShellExtMenu
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Misosh.MShellExtMenu.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB85C504-C730-49DD-BEC1-7B39C6103B7A}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\MagicISO
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\MagicISO
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB85C504-C730-49DD-BEC1-7B39C6103B7A}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MagicISO.Document\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MagicISO.Document\shell\open\command
HKEY_CURRENT_USER\Software\WinRAR SFX
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Misosh.MShellExtMenu\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Magic ISO Maker v5.3 (build 0221)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\MagicISO
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.uif
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB85C504-C730-49DD-BEC1-7B39C6103B7A}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MagicISO.Document
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MagicISO.Document\shell\open
HKEY_CURRENT_USER\Software\MagicISO
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Misosh.MShellExtMenu\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Misosh.MShellExtMenu.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB85C504-C730-49DD-BEC1-7B39C6103B7A}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.iso
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB85C504-C730-49DD-BEC1-7B39C6103B7A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB85C504-C730-49DD-BEC1-7B39C6103B7A}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MagicISO.Document\shell

Trending

Most Viewed

Loading...