HPsus/Banload-A

Category: Suspicious Behavior and Files Protection available since:05 Sep 2012 14:29:42 (GMT)
Type: Suspicious file Last Updated:05 Sep 2012 14:29:42 (GMT)

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of HPsus/Banload-A include:

Example 1

File Information

Size
440K
SHA-1
0162a8609a9f5e7e1ba7b7dadaface96c39dd0e5
MD5
85c62c0199236508aae6dd21af0ee28c
CRC-32
a80cbc44
File type
Windows executable
First seen
2011-02-17

Runtime Analysis

Copies Itself To
  • C:\WINDOWS\system32\skype\install.exe

Example 2

File Information

Size
436K
SHA-1
2e00952da7bf98b2270ee2824c4037b45a174ae6
MD5
43f4a71ff0232767320d64848fbf4cf1
CRC-32
b064e226
File type
Windows executable
First seen
2011-02-22

Runtime Analysis

Copies Itself To
  • C:\WINDOWS\system32\skype\install.exe
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    test_item.exe
    C:\windows\system32\skype\install.exe

Example 3

File Information

Size
440K
SHA-1
44ae54607eefeb7dcfd3537d1bd59c360552329e
MD5
7efddd7f6712d1995cdf8ba14a730be2
CRC-32
6a3a0f51
File type
Windows executable
First seen
2011-03-27

Runtime Analysis

Copies Itself To
  • C:\WINDOWS\system32\skype\install.exe

download Try Sophos products for free
Download now