Troj/Reveton-BD

Category: Viruses and Spyware Protection available since:11 Dec 2012 14:51:54 (GMT)
Type: Trojan Last Updated:11 Dec 2012 14:51:54 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Reveton-BD exhibits the following characteristics:

File Information

Size
258K
SHA-1
13ceb4f0a0888cd9038a52d3b844d52b28d7c4c9
MD5
13c5c4a0dc53db49941595c9b67894c2
CRC-32
880da428
File type
Windows executable
First seen
2007-07-11

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Start Menu\Programs\Startup\runctf.lnk
    Size
    740
    SHA-1
    c4564dd71ad3f41939a866b33d004cc4d5321d01
    MD5
    569118d0de14ba5cc5c280e21128a20d
    CRC-32
    c48e7f73
    File type
    Windows Shortcut file (.LNK)
    First seen
    2012-12-11
  • C:\Documents and Settings\All Users\Application Data\elpmas.pad
    Size
    91M
    SHA-1
    c658996a0abfae36a445dbe8129591f09aede1af
    MD5
    6dba20383fe7f4992ef7b4198c79d952
    CRC-32
    57e44a83
    File type
    Unspecified binary - probably data
    First seen
    2012-12-11
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    2500
    0x00000003
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
    2500
    0x00000003
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
    2500
    0x00000003
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
    2500
    0x00000003
  • HKCU\Software\Microsoft\Internet Explorer\Main
    NoProtectedModeBanner
    0x00000001
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
    2500
    0x00000003
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
    1609
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    1609
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
    1609
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
    1609
    0x00000000
IP Connections
  • 146.185.255.219:80

download Try Sophos products for free
Download now