Troj/MSIL-AU exhibits the following characteristics:
File Information
- Size
- 629K
- SHA-1
- 56a37fb87bd03db757e7ce32d4cf6d6428fb1ce4
- MD5
- 1372588e40640aa8c5c13d880e7e5c39
- CRC-32
- 5204128e
- File type
- Windows executable
- First seen
- 2012-03-30
Other vendor detection
- Kaspersky
- Trojan-Dropper.Win32.Injector.dopg
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Start Menu\Programs\Startup\svhost.exe
Dropped Files
- c:\Documents and Settings\test user\Application Data\cryptergeer
- Size
- 32
- SHA-1
- 7fd33378c3802ddc3517a78bb50c671c502958e6
- MD5
- 6dbfaca500fb118badde11dd182f5e3d
- CRC-32
- 087b39ad
- File type
- Data Log File (generic)
- First seen
- 2012-12-28
- c:\Documents and Settings\test user\Local Settings\Temp\svchost.exe
- c:\Documents and Settings\test user\Application Data\DriverComp.exe
Registry Keys Created
- HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- c:\Documents and Settings\test user\Application Data\DriverComp.exe
- c:\Documents and Settings\test user\Application Data\DriverComp.exe:*:Enabled:Windows Messanger
- HKCU\Software\VB and VBA Program Settings\INSTALL\DATE
- 5X7V5FINRP
- December 28, 2012
- HKCU\Software\VB and VBA Program Settings\SrvID\ID
- 5X7V5FINRP
- Cryptergeer
Registry Keys Modified
- HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
- DoNotAllowExceptions
- 0x00000000
Processes Created
- c:\Documents and Settings\test user\local settings\temp\svchost.exe
- c:\windows\system32\cmd.exe
- c:\windows\system32\reg.exe
DNS Requests