Troj/Spy-XR

Category: Viruses and Spyware Protection available since:10 Aug 2011 10:44:42 (GMT)
Type: Trojan Last Updated:10 Aug 2011 10:44:42 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/Spy-XR include:

Example 1

File Information

Size
76K
SHA-1
1a847ed28da912dd43ecff8a9c95e9305e9dffec
MD5
dbf455f29260b59b21b8407c55b6ebfb
CRC-32
93670d13
File type
application/x-ms-dos-executable
First seen
2011-08-08

Example 2

File Information

Size
108K
SHA-1
540a885ba1bb3815b2b2040bc792127c34760409
MD5
92153915eef1405dfcf5556a5977f224
CRC-32
135f04c1
File type
Windows executable
First seen
2011-06-03

Runtime Analysis

Dropped Files
  • C:\WINDOWS\ime\wmimachine2.dll
    Size
    76K
    SHA-1
    d8b91a7d5758af9c164dcef25945250be3052b7e
    MD5
    5e4253897f74ece84df9229cdd66d345
    CRC-32
    e7639ad5
    File type
    Windows executable
    First seen
    2011-06-03
Registry Keys Created
  • HKLM\SYSTEM\CurrentControlSet\Services\6to4
    Start
    0x00000002
  • HKLM\SYSTEM\CurrentControlSet\Services\6to4\Parameters
    ServiceDll
    C:\WINDOWS\ime\wmimachine2.dll
  • HKLM\SYSTEM\CurrentControlSet\Services\6to4\Enum
    Count
    0x00000001
DNS Requests
  • connectsexy.dns-dns.com

Example 3

File Information

Size
76K
SHA-1
d8b91a7d5758af9c164dcef25945250be3052b7e
MD5
5e4253897f74ece84df9229cdd66d345
CRC-32
e7639ad5
File type
Windows executable
First seen
2011-06-03

download Try Sophos products for free
Download now