FakeAV.SE_5 is a Trojan. A Trojan is a program that pretends to have a valid use, but in fact modifies the user's computer in malicious ways. Trojans do not replicate or spread to other computers. Process Related Changes It creates the following mutex(es): - CTF.TMD.MutexDefaultS-1-5-21-1078081533-842925246-854245398-1003"
- 138fb9d7ccfa67d3c8d580aed4b632bb"
- CTF.TimListCache.FMPDefaultS-1-5-21-1078081533-842925246-854245398-1003MUTEX.DefaultS-1-5-21-1078081533-842925246-854245398-1003"
- CTF.Compart.MutexDefaultS-1-5-21-1078081533-842925246-854245398-1003"
- CTF.Layouts.MutexDefaultS-1-5-21-1078081533-842925246-854245398-1003"
- CTF.Asm.MutexDefaultS-1-5-21-1078081533-842925246-854245398-1003"
- CTF.LBES.MutexDefaultS-1-5-21-1078081533-842925246-854245398-1003"
It creates the following process(es): - C:\WINDOWS\Temp\cd52d17bfb0b612320362db9182f5e96.exe [ \c:\windows\temp\cd52d17bfb0b612320362db9182f5e96.exe ]
Network Activity We observed the following DNS query/queries: - miledaughter.ru
- determineport.ru
- mixftinvkohgi.nod-crash-face.top
|