Troj/Agent-AAPL

Category: Viruses and Spyware Protection available since:11 Mar 2013 13:19:46 (GMT)
Type: Trojan Last Updated:11 Mar 2013 13:19:46 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Agent-AAPL exhibits the following characteristics:

File Information

Size
728K
SHA-1
dda993d1474f401b62cc3a3b059316375e1c2735
MD5
764342cd2d38ac617741803fa9cbcc3e
CRC-32
fd135203
File type
Windows executable
First seen
2011-11-17

Runtime Analysis

Copies Itself To
  • F:/23556fb1360f366337f97c924e76ead3.exe
  • c:\Documents and Settings\test user\Application Data\svchost.exe
  • c:\Documents and Settings\test user\Start Menu\Programs\Startup\23556fb1360f366337f97c924e76ead3.exe
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    23556fb1360f366337f97c924e76ead3
    "c:\Documents and Settings\test user\Application Data\svchost.exe" ..
  • HKCU\Software\23556fb1360f366337f97c924e76ead3
    US
    !
  • HKCU\Environment
    SEE_MASK_NOZONECHECKS
    1
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    23556fb1360f366337f97c924e76ead3
    "c:\Documents and Settings\test user\Application Data\svchost.exe" ..
Processes Created
  • c:\Documents and Settings\test user\application data\svchost.exe
  • c:\windows\system32\netsh.exe
DNS Requests
  • titi77.zapto.org

download Try Sophos products for free
Download now