Home Malware Programs Trojans Trojan.Chromext

Trojan.Chromext

Posted: December 4, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 12
First Seen: December 4, 2012
Last Seen: November 8, 2024
OS(es) Affected: Windows

Trojan.Chromext is a Trojan that steals personal information and opens a back door on the infected computer. Trojan.Chromext is downloaded and installed as a Chrome browser extension. Trojan.Chromext then attempts to steal user names and passwords entered into the Chrome browser. Trojan.Chromext also attempts to steal cookies stored in the web browser. Once executed, Trojan.Chromext may download numerous potentially malicious files from the remote server. Trojan.Chromext also gathers the affected PC user's personal information and transmits it to a remote server. Trojan.Chromext opens a back door on the corrupted PC and waits for commands given by the remote attacker.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1.c File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1.c
Mime Type: unknown/c
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\LICENSE File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\LICENSE
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\TODO File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\TODO
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1.h File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1.h
Mime Type: unknown/h
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\icon.png File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\icon.png
Mime Type: unknown/png
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\Makefile File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\Makefile
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\INSTALL File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\INSTALL
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\main.js File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\main.js
File type: JavaScript file
Mime Type: unknown/js
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\jquery.min.js File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\jquery.min.js
File type: JavaScript file
Mime Type: unknown/js
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\background.js File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\background.js
File type: JavaScript file
Mime Type: unknown/js
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack.nmf File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack.nmf
Mime Type: unknown/nmf
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_64.o File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_64.o
Mime Type: unknown/o
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\make.bat File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\make.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\manifest.json File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\manifest.json
Mime Type: unknown/json
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\background.html File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\background.html
Mime Type: unknown/html
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack.cc File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack.cc
Mime Type: unknown/cc
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\pack_extension - Copy.bat File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\pack_extension - Copy.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_x86_32.nexe File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_x86_32.nexe
Mime Type: unknown/nexe
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\pack_extension.bat File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\pack_extension.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_32.o File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_32.o
Mime Type: unknown/o
Group: Malware file
%UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_x86_64.nexe File name: %UserProfile%\Application Data\Google\Chrome\User Data\Default\Extensions\fmphgefonmnoadmehmejfjnbmgoolboc\[EXTENSION VERSION]\sha1_pwcrack_x86_64.nexe
Mime Type: unknown/nexe
Group: Malware file
Loading...