Troj/Agent-ZTO

Category: Viruses and Spyware Protection available since:30 Jan 2013 08:10:29 (GMT)
Type: Trojan Last Updated:30 Jan 2013 08:10:29 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Agent-ZTO exhibits the following characteristics:

File Information

Size
52K
SHA-1
9b71d9b8dffa8e3504bfc00ae228cb6f2fe4097f
MD5
f3826facbc72766ccc7fdee65e730e35
CRC-32
fc7c9e24
File type
Windows executable
First seen
2013-01-30

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\Wwopj\gccfbvmu.exe
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    vjkubvmu
    c:\Documents and Settings\test user\Application Data\Wwopj\gccfbvmu.exe
Processes Created
  • c:\docume~1\support\locals~1\temp\irivycfsll.pre
  • c:\windows\system32\ctfmon.exe
  • c:\windows\system32\svchost.exe
HTTP Requests
  • http://kcrio-oum.com/typo3.php
DNS Requests
  • kcrio-oum.com

download Try Sophos products for free
Download now