Troj/FakeAV-DCT

Category: Viruses and Spyware Protection available since:01 Apr 2011 19:08:19 (GMT)
Type: Trojan Last Updated:01 Apr 2011 19:08:19 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/FakeAV-DCT include:

Example 1

File Information

Size
64K
SHA-1
2145a02e97f1033434207117d78c0ee7398f74b0
MD5
d3687bbeaf22aae3219b952198c9500c
CRC-32
97332504
File type
application/x-ms-dos-executable
First seen
2011-04-01

Other vendor detection

Avira
TR/Crypt.ZPACK.Gen
Kaspersky
Trojan-Downloader.Win32.Genome.cges

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Temp\mv2.tmp
HTTP Requests
  • http://miners.co.be/LcydApxIpjyL7P3oeG3gMfRPE+4Xg2iXRWLH6qN+Hdlt48m+A1Dw5LeRGg6kljrnP1uw4kxnYcxyCCMNKf+FQgrA0XjUPZYHgTC/wTIcEGw=
  • http://miners.co.be/utDYtoXpoflgiM+M6g8vbCw01GOHM+FD8of2Ii+3HmDtpZG3/4/KAjavOiO+bjQ5/xzJ2PP17rGwp63A
DNS Requests
  • miners.co.be

Example 2

File Information

Size
64K
SHA-1
2958e0e3007b0149f69b5c868a00b742f1167492
MD5
4704213868e106e1ef76378191a4d026
CRC-32
a9608159
File type
application/x-ms-dos-executable
First seen
2011-04-01

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Temp\mv2.tmp
HTTP Requests
  • http://ellled.co.be/FfNQzUhodVUPsBKaaXISTQ2d8l9vmVEdvir+9dw2cs64mX4vBj6g/4nM59H5wIbW3bW5BvEAUqVk3Ieb
  • http://ellled.co.be/xUfluqHfDrExqQdFgv4z1E5sQnjX29vNK97wpmMPCsRPTY9LyzUf46H1bRa17+c6dM3HS7LwPf7F1YnV8w2kiyzFpiBM45NSeOd5KUaFbF0=
DNS Requests
  • ellled.co.be

Example 3

File Information

Size
64K
SHA-1
4a2eaf1e4461c9533980b7dfd6e2da440bf73925
MD5
2361bf621e863b5310a23c70c33e7210
CRC-32
cf12a121
File type
application/x-ms-dos-executable
First seen
2011-03-31

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Temp\mv2.tmp
HTTP Requests
  • http://celosa.co.be/HCSRuqIvBCmelb1XZVG8xH7LYCPOTiuO3mv4Jf2WgGnqWUTuU9AU36ikBkga8oumqCALLkrw93hTlFZQ
  • http://celosa.co.be/bCXyAeEwtANYd3ZF5DseznAEi0Ylex8Hp2+51eWxoSWlyruS6Q3F8kQjq7kfDCywqP2BBCLgBfdkqtlWPaU9as4QygMSk+VZzBNMIt7q4tQ=
DNS Requests
  • celosa.co.be

download Try Sophos products for free
Download now