Threat Database Trojan Downloader TrojanDownloader:Win32/Kanav.F

TrojanDownloader:Win32/Kanav.F

By Sumo3000 in Trojan Downloader

Threat Scorecard

Popularity Rank: 9,643
Threat Level: 10 % (Normal)
Infected Computers: 306
First Seen: February 6, 2013
Last Seen: February 4, 2026
OS(es) Affected: Windows

TrojanDownloader:Win32/Kanav.F is a Trojan that drops and runs other malware infections on the corrupted PC. TrojanDownloader:Win32/Kanav.F also deletes a registry entry, if it is found, that's related to online gaming. When installed, TrojanDownloader:Win32/Kanav.F makes system changes by adding malevolent files. TrojanDownloader:Win32/Kanav.F creates the registry entry so that it can launch its copy automatically whenever Windows is started. TrojanDownloader:Win32/Kanav.F queries certain websites, which may return an encrypted string. When decrypted, the string tells TrojanDownloader:Win32/Kanav.F where to drop and run other files. TrojanDownloader:Win32/Kanav.F deletes gaming settings. TrojanDownloader:Win32/Kanav.F also deletes the registry entry, if the victim has it in the PC. TrojanDownloader:Win32/Kanav.F steals information about the affected computer system, which it transfers to 'exeinfo1.org'.

File System Details

TrojanDownloader:Win32/Kanav.F may create the following file(s):
# File Name Detections
1. %ProgramFiles%\Common Files\Apple\Mobile Device Support\apple.exe

Registry Details

TrojanDownloader:Win32/Kanav.F may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Blizzard Entertainment\Battle.net\Identity
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\[RANDOM CLSID] "stubpath" = "%ProgramFiles%\Common Files\Apple\Mobile Device Support\apple.exe

Analysis Report

General information

Family Name: PUP.Loader
Signature status: No Signature

Known Samples

MD5: e822d88b1862ee710a6d79bc36b0ea77
SHA1: 1978fe0a48a6e208a059166b48e88b08f4f6f875
File Size: 537.09 KB, 537088 bytes
MD5: 9603c6b1f51a3a1d99cd5b713fbe974f
SHA1: e591383b9dd43ade212bc4da3b7e4c17c18d87b3
SHA256: 929A2064BA080764079B194E74D28F80AAA3D0C0CB0108E2C3EED07CE985FFB4
File Size: 125.44 KB, 125440 bytes
MD5: acd2bc0879917731dbd06f6a02d5e16d
SHA1: 6c762f0b464fe74c6c0442cf82215221775a7ab9
SHA256: D460B273626C1DACF03A68A3EB392E080D72C7B6ECF13AC1DAEDC15F4133E700
File Size: 23.55 KB, 23552 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 4.5.0.0
  • 1.1.0.0
Comments
  • AnyDVD leftover killer
  • DocsVision Applications Designer Model Component
Company Name
  • DocsVision
  • Dr.Pc Putte Corporation 😉
  • Heidelberg Engineering GmbH
File Description
  • AnyDVD leftover killer
  • BackOffice Model
  • PersistenceSpectralis
File Version
  • 4.5.2024.8344
  • 1.1.1760.24746
  • 1.00
Internal Name
  • AnyDVD_leftover_killer
  • DocsVision.BackOffice.Model.dll
  • PersistenceSpectralis.dll
Legal Copyright
  • Copyright (c) Heidelberg Engineering GmbH
  • Copyright © 2001-2009 DocsVision. All rights reserved.
  • Dr.Pc Putte
Legal Trademarks Dr.Pc Putte Corporation 😉
Original Filename
  • AnyDVD_leftover_killer.exe
  • DocsVision.BackOffice.Model.dll
  • PersistenceSpectralis.dll
Product Name
  • AnyDVD leftover killer
  • DocsVision 4.5
  • PersistenceSpectralis
Product Version
  • 4.5
  • 1.1.0.0
  • 1.00

File Traits

  • .NET
  • dll
  • HighEntropy
  • packed
  • UPX!
  • x64
  • x86

Block Information

Total Blocks: 2
Potentially Malicious Blocks: 1
Whitelisted Blocks: 1
Unknown Blocks: 0

Visual Map

x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserSetWindowPos
  • win32u.dll!NtUserUpdateInputContext

Trending

Most Viewed

Loading...