Troj/Agent-AAPL exhibits the following characteristics:
File Information
- Size
- 728K
- SHA-1
- dda993d1474f401b62cc3a3b059316375e1c2735
- MD5
- 764342cd2d38ac617741803fa9cbcc3e
- CRC-32
- fd135203
- File type
- Windows executable
- First seen
- 2011-11-17
Runtime Analysis
Copies Itself To
- F:/23556fb1360f366337f97c924e76ead3.exe
- c:\Documents and Settings\test user\Application Data\svchost.exe
- c:\Documents and Settings\test user\Start Menu\Programs\Startup\23556fb1360f366337f97c924e76ead3.exe
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- 23556fb1360f366337f97c924e76ead3
- "c:\Documents and Settings\test user\Application Data\svchost.exe" ..
- HKCU\Software\23556fb1360f366337f97c924e76ead3
- US
- !
- HKCU\Environment
- SEE_MASK_NOZONECHECKS
- 1
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- 23556fb1360f366337f97c924e76ead3
- "c:\Documents and Settings\test user\Application Data\svchost.exe" ..
Processes Created
- c:\Documents and Settings\test user\application data\svchost.exe
- c:\windows\system32\netsh.exe
DNS Requests