Troj/Killav-IB

Category: Viruses and Spyware Protection available since:11 Dec 2012 14:51:54 (GMT)
Type: Trojan Last Updated:11 Dec 2012 14:51:54 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/Killav-IB include:

Example 1

File Information

Size
32K
SHA-1
5deb07503e212e23e1f6d23b7fd93289da20061f
MD5
d542fd20caac2c34bbec498c05b0d828
CRC-32
51104854
File type
Windows executable
First seen
2012-11-23

Example 2

File Information

Size
280K
SHA-1
7d53c1b883391da8d2d9b28c4a255fbcfec7cce1
MD5
b286f1b7b6b27977b7a8c161e4ae6a02
CRC-32
41f38d33
File type
Windows executable
First seen
2012-11-29

Other vendor detection

Avira
TR/Dropper.Gen

Runtime Analysis

Dropped Files
  • C:\servicesc.exe
    Size
    32K
    SHA-1
    5deb07503e212e23e1f6d23b7fd93289da20061f
    MD5
    d542fd20caac2c34bbec498c05b0d828
    CRC-32
    51104854
    File type
    Windows executable
    First seen
    2012-11-23
  • c:\Documents and Settings\test user\Local Settings\Temp\~DF330C.tmp
  • c:\Documents and Settings\test user\Local Settings\Temp\~DF16BF.tmp
Registry Keys Created
  • HKCU\Software\Microsoft\Internet Explorer\International\CpMRU
    Factor
    0x00000014
Processes Created
  • c:\servicesc.exe
HTTP Requests
  • http://c.cnzz.com/cnzz_core.php
  • http://c.l7l73.net.cn/test/ku62.asp
  • http://hzs17.cnzz.com/stat.htm
  • http://s17.cnzz.com/stat.php
  • http://uu.wangbagou.com/tongji.asp
  • http://www.hao123.com/
DNS Requests
  • c.cnzz.com
  • c.l7l73.net.cn
  • hzs17.cnzz.com
  • s17.cnzz.com
  • uu.wangbagou.com
  • www.hao123.com

download Try Sophos products for free
Download now