Threat Database Trojans Trojan.Reveton.D

Trojan.Reveton.D

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,202
Threat Level: 80 % (High)
Infected Computers: 140
First Seen: August 21, 2012
Last Seen: December 8, 2025
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
AVG Generic27.APPC
AntiVir TR/Reveton.D.2
Avast Win32:SmokeLoader-OK [Trj]
NOD32 a variant of Win32/Kryptik.ACHY
CAT-QuickHeal Trojan.Reveton
AVG Generic27.AGWO
AntiVir TR/Crypt.ULPM.Gen
Sophos Mal/Bredo-RH
eSafe Win32.Trojan
Avast Win32:Kryptik-HUI [Trj]
McAfee Generic.dx!bdht
AVG Downloader.Generic_r.LI
AntiVir TR/Reveton.D
Avast Win32:Buterat-IY [Trj]
Symantec Suspicious.Cloud.5

File System Details

Trojan.Reveton.D may create the following file(s):
# File Name MD5 Detections
1. C860A046F7934EBC36672B76381C1C.exe b0e8f96757118f269efb8a59397e7350 37
2. NEUSBw32.dll 0e0ec1295c911bd5ed1e5e6f82682f8e 14
3. B7FE292E2F4F2F93EAFBDA4BB79EB2D.exe c041cc899f40924ca294c35e2d4ed5aa 12
4. E8D0DD5AC6A878E1777F65A44D05CC.exe 3be88acab515e0b200ce90c2b9fcd339 11
5. USB3Sw32.dll eb14098ae7c1ae271b852461e6c673c8 10
6. sched.exe 5cd877dbd7cb52f1c18edad5e2124031 10
7. nd.bin 0c08b0025cedb99b044cafa0c6c51658 8
8. BB31817AC617EBE10D69DADB67E2424.exe d5f15e9c0bcbea6e1470e74a2a2a6ed2 8
9. appmgmts.dll 669f12a7895495f25a2cdc20bb7f7089 7
10. svchost2.exe 978126c1779d85051f4e54455fe8886a 2
11. KML81V7a.exe 5bdc80122320d28c3f534ae4691fa611 2
12. pxkshxta.exe 2d02c6290ba42e63f00fd3b1a8dae810 2
13. 4454F1A831D76E378B738CBDF0422CE.exe 4be47dbf9c197d41f676ceaf8b432b93 2

Analysis Report

General information

Family Name: Trojan.Reveton.D
Signature status: No Signature

Known Samples

MD5: f2851a212d7493c1355b69c1709b9c1f
SHA1: 832644a01749e24121a44da11fcaa6f46f427e85
SHA256: 5D09D46D1BD546EFD7F1C6EE8FB63394C7CB59B03F5D3D1E7A7C05F7073ED4E7
File Size: 1.54 MB, 1537425 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name Lark AntiSpyware, Inc.
File Description Lark AntiSpyware Setup
Product Name Lark AntiSpyware

File Traits

  • 2+ executable sections
  • x86

Trending

Most Viewed

Loading...