Troj/Agent-YFA

Category: Viruses and Spyware Protection available since:12 Oct 2012 01:53:04 (GMT)
Type: Trojan Last Updated:12 Oct 2012 01:53:04 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Agent-YFA exhibits the following characteristics:

File Information

Size
65K
SHA-1
64f12372d3383fe304554279d7899eda2b0906ef
MD5
a1469208d2bf251c7eb8074aab828fc1
CRC-32
05c02bea
File type
Windows executable
First seen
2012-10-11

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\937e_appcompat.txt
  • c:\Documents and Settings\test user\Local Settings\Temp\7fd6_appcompat.txt
  • c:\Documents and Settings\test user\Local Settings\Temp\2f79_appcompat.txt
Registry Keys Created
  • HKCU_Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\inprocserver32
    (Default)
    C:\DOCUME~1\support\LOCALS~1\Temp\\tcrcfg\rcjxyn:weaeml.
  • HKCU\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\inprocserver32
    (Default)
    C:\DOCUME~1\support\LOCALS~1\Temp\\tcrcfg\rcjxyn:weaeml.
Processes Created
  • c:\windows\system32\svchost.exe
HTTP Requests
  • http://37.220.36.44/logum.php
IP Connections
  • 37.220.36.44:80

download Try Sophos products for free
Download now