Troj/DwnLdr-KNO

Category: Viruses and Spyware Protection available since:23 Jan 2013 23:52:41 (GMT)
Type: Trojan Last Updated:23 Jan 2013 23:52:41 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/DwnLdr-KNO include:

Example 1

File Information

Size
48K
SHA-1
9cfd61ede466b277f927fc4093d9f65e57f24c3f
MD5
0e6d3e3fd8de28a72a46e2f9c006e156
CRC-32
c9c1a056
File type
Windows executable
First seen
2012-11-18

Runtime Analysis

Copies Itself To
  • C:\Documents and Settings\All Users\svchost.exe
Dropped Files
  • c:\Documents and Settings\test user\Application Data\cBkr36GVD7.exe
    Size
    48K
    SHA-1
    a0eaf4eb377f685e6ff2d13bbed6d0601fc0e97f
    MD5
    1c8b0244d17c0fa8ef4eeaeb2175010e
    CRC-32
    c7961efc
    File type
    Windows executable
    First seen
    2012-11-19
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    SunJavaUpdateSched
    C:\Documents and Settings\All Users\svchost.exe
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    Microsoft
    c:\Documents and Settings\test user\Application Data\cBkr36GVD7.exe

Example 2

File Information

Size
48K
SHA-1
a0eaf4eb377f685e6ff2d13bbed6d0601fc0e97f
MD5
1c8b0244d17c0fa8ef4eeaeb2175010e
CRC-32
c7961efc
File type
Windows executable
First seen
2012-11-19

download Try Sophos products for free
Download now