Mal/VBCheMan-D

Category: Viruses and Spyware Protection available since:29 Mar 2012 11:18:57 (GMT)
Type: Malicious behavior Last Updated:05 Jan 2013 05:08:20 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Mal/VBCheMan-D include:

Example 1

File Information

Size
148K
SHA-1
00129b1375ba75a6820b2eca06764c26c4eb16e2
MD5
57e82d771f67223092d6b59273227407
CRC-32
abd9a8a2
File type
application/x-ms-dos-executable
First seen
2011-07-21

Example 2

File Information

Size
153K
SHA-1
0049d47c6b8dfd57779bb7b9257914870a3e9b99
MD5
821f36f08e55c4efe9fcd5f61d13cc0d
CRC-32
1e0d11b9
File type
Windows executable
First seen
2011-06-27

Example 3

File Information

Size
412K
SHA-1
00587870d0b8306a9272d39f6cfaf70483f85162
MD5
159a7d6fbe8b3a6cdd1914b362a1a717
CRC-32
343a6ef3
File type
application/x-ms-dos-executable
First seen
2011-08-02

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\Microsoft\taskmng.exe
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    csrss
    c:\Documents and Settings\test user\Application Data\Microsoft\taskmng.exe
Processes Created
  • c:\Documents and Settings\test user\application data\microsoft\taskmng.exe
DNS Requests
  • mikedns.no-ip.org

download Try Sophos products for free
Download now