Troj/Inject-AFK

Category: Viruses and Spyware Protection available since:27 Feb 2013 12:50:10 (GMT)
Type: Trojan Last Updated:27 Feb 2013 12:50:10 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Inject-AFK exhibits the following characteristics:

File Information

Size
1.3M
SHA-1
4a99aa6b7ee01bc4a3143f92a16efc3837a58bb9
MD5
2e84d750e626e84a6d837901899cf1b0
CRC-32
335ca00b
File type
application/x-ms-dos-executable
First seen
2013-02-27

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\WEAREROSES\WEAREROSES.exe
Registry Keys Created
  • HKCU\Software\Microsoft Windows Update
    ID
    B5peyUHQVqotwUSif3BTJLf3umpxRYN
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    Microsoft Windows Update
    c:\Documents and Settings\test user\Application Data\WEAREROSES\WEAREROSES.exe
Processes Created
  • c:\windows\system32\notepad.exe
DNS Requests
  • ozooloya.no-ip.org

download Try Sophos products for free
Download now