Threat Database Viruses Virus.Injector.AC

Virus.Injector.AC

By CagedTech in Viruses

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 37
First Seen: June 6, 2011
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Ikarus Trojan.Win32.Pakes
AhnLab-V3 Win-Trojan/Pakes.172034
Sophos Troj/Scar-AS
BitDefender Trojan.Generic.KDV.202347
Kaspersky Trojan.Win32.Pakes.oyw
Avast Win32:Renos-APQ
Symantec Trojan.ADH
K7AntiVirus Trojan
McAfee Generic.dx!zsd
CAT-QuickHeal Trojan.Pakes.oyw
Panda Trj/CI.A
AVG PSW.Generic8.BQYI
Ikarus Trojan-Ransom.Win32.Gimemo
AntiVir TR/Ransom.Gimemo.aqr
Kaspersky HEUR:Trojan.Win32.Generic

File System Details

Virus.Injector.AC may create the following file(s):
# File Name MD5 Detections
1. verupd.exe 8b142058a062ee5fcd065853262c83f1 27
2. $Recycle$.exe eb54df0d8f536f3d380bd21cb0c3d1db 5
3. systemupdate.exe 98df6b1557a1954d7a8200da4f4b3f87 2
4. facebook-pic0002005198114.exe 39422045199d8889956b867ff488f7d6 1
5. Washer2.rar.exe e132be2f373c0ffcffc6e7b8be5678cd 1
6. Pniaip.exe 2e450bd99d05d90a80837c0a1ff003b7 1

Analysis Report

General information

Family Name: Trojan.Injector.AC
Signature status: No Signature

Known Samples

MD5: f8b78c462771a6318cfd7a97f07a42fd
SHA1: 26a0ad22f293b7d52908405259aa4e52486324dc
SHA256: 035887D0368F699703C7D219AAC3B5AE9E9098D456D2B36E7D88B0FC5FD6AB90
File Size: 45.06 KB, 45056 bytes
MD5: b8d1e4614e4ed55527af09215b215f66
SHA1: 101a907787d7e8cf3602e57f4dfcc06cd2766782
SHA256: 1996A0CD1D605C9BDB899BF5085CE3C458ED9627B1A7F0391181AA616B747C59
File Size: 548.86 KB, 548864 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • AVS Digital Version
  • Steel Run As
Company Name
  • Steelsonic Technical Services
  • www.aaa-multimedia.com
File Description AVS executable (VB6)
File Version
  • 7.01.0281
  • 1.05.0009
Internal Name
  • AVS_1280x768
  • template.sst
Legal Copyright www.aaa-multimedia.com 2002
Legal Trademarks Inneractive Aura Video Station
Original Filename
  • AVS_1280x768.exe
  • template.sst.exe
Product Name
  • Aura Video Station
  • Steel Run-As
Product Version
  • 7.01.0281
  • 1.05.0009

File Traits

  • vb6
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\~df12ed2fe74eb7cf75.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~df4146de0d8217184a.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...