Trojan.Win32.Killav.br

tag:Trojans  

0 0

This Trojan will terminate a range of legitimate programs on the victim machine. The Trojan itself is a Windows PE EXE file 4608 bytes in size.

Installation

Once launched, the Trojan creates a file called mserv.exe, 6656 bytes in size, in the Windows root directory:

%Windir%/mserv.exe

The Trojan then creates the following entries in the system registry:

[HKLM\System\CurrentControlSet001\Enum\Root\LEGACY_ANEM]
Service="anem"
Legacy="dword:00000001"
Class="LegacyDriver"
DeviceDesc="mserv.exe" Payload

©Virus-Encyclopedia.com All Rights Reserved.