Troj/DwnLdr-KOC

Category: Viruses and Spyware Protection available since:28 Jan 2013 04:08:05 (GMT)
Type: Trojan Last Updated:28 Jan 2013 04:08:05 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/DwnLdr-KOC exhibits the following characteristics:

File Information

Size
161K
SHA-1
afb094fcf9a54515f8f111b0576fb0f466ecc4ac
MD5
20057f1155515dd3a37afde0b459b2cf
CRC-32
0cfe4035
File type
Windows executable
First seen
2013-01-27

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\xxgfrdqs.exe
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    MSConfig
    "c:\Documents and Settings\test user\xxgfrdqs.exe"
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    Administrative Tools
    c:\Documents and Settings\test user\Start Menu\Programs\Administrative Tools
Processes Created
  • c:\Documents and Settings\test user\xxgfrdqs.exe
  • c:\windows\system32\cmd.exe
  • c:\windows\system32\svchost.exe
IP Connections
  • 91.218.38.245:443

download Try Sophos products for free
Download now