Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:TR/Qhost.kng
Date discovered:22/10/2008
Type:Trojan
In the wild:Yes
Reported Infections:Low
Distribution Potential:Low to medium
Damage Potential:Low
Static file:Yes
File size:185.392 Bytes
MD5 checksum:f14f89211fd6723b4e245502ddcb7eff
IVDF version:7.00.07.73 - Wednesday, October 22, 2008

 General Method of propagation:
    Autorun feature


Aliases:
   •  Panda: Trj/Qhost.JT
   •  Eset: Win32/Agent.OKD
   •  Bitdefender: Trojan.Downloader.JLEL


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003


Side effects:
   • Downloads a malicious file
   • Drops a malicious file

 Files It deletes the initially executed copy of itself.



The following file is created:

%TEMPDIR%\80f12af693cc3e052327e4e33e68f4ca.bat



It tries to download a file:

The location is the following:
   • http://wl.dwen24.com/v306/**********
At the time of writing this file was not online for further investigation.

 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Açıklamayı yerleştiren Petre Galan tarihinde 1 Mart 2010 Pazartesi
Açıklamayı güncelleyen: Petre Galan tarihinde 2 Mart 2010 Salı

Geri . . . .
https:// Bu pencere güvenlik amacıyla şifrelenmiştir.