Troj/MSIL-AU

Category: Viruses and Spyware Protection available since:29 Dec 2012 05:46:49 (GMT)
Type: Trojan Last Updated:29 Dec 2012 05:46:49 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/MSIL-AU exhibits the following characteristics:

File Information

Size
629K
SHA-1
56a37fb87bd03db757e7ce32d4cf6d6428fb1ce4
MD5
1372588e40640aa8c5c13d880e7e5c39
CRC-32
5204128e
File type
Windows executable
First seen
2012-03-30

Other vendor detection

Kaspersky
Trojan-Dropper.Win32.Injector.dopg

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Start Menu\Programs\Startup\svhost.exe
Dropped Files
  • c:\Documents and Settings\test user\Application Data\cryptergeer
    Size
    32
    SHA-1
    7fd33378c3802ddc3517a78bb50c671c502958e6
    MD5
    6dbfaca500fb118badde11dd182f5e3d
    CRC-32
    087b39ad
    File type
    Data Log File (generic)
    First seen
    2012-12-28
  • c:\Documents and Settings\test user\Local Settings\Temp\svchost.exe
  • c:\Documents and Settings\test user\Application Data\DriverComp.exe
Registry Keys Created
  • HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
    c:\Documents and Settings\test user\Application Data\DriverComp.exe
    c:\Documents and Settings\test user\Application Data\DriverComp.exe:*:Enabled:Windows Messanger
  • HKCU\Software\VB and VBA Program Settings\INSTALL\DATE
    5X7V5FINRP
    December 28, 2012
  • HKCU\Software\VB and VBA Program Settings\SrvID\ID
    5X7V5FINRP
    Cryptergeer
Registry Keys Modified
  • HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
    DoNotAllowExceptions
    0x00000000
Processes Created
  • c:\Documents and Settings\test user\local settings\temp\svchost.exe
  • c:\windows\system32\cmd.exe
  • c:\windows\system32\reg.exe
DNS Requests
  • dutchops.no-ip.info

download Try Sophos products for free
Download now