W32/Cryptic.KE Trojan
| Name |
W32/Cryptic.KE Trojan |
| Aliases |
Trojan-Downloader.Win32.Cryptic.ke |
| Discovered on |
May 02, 2008 |
Virus Information - W32/Cryptic.KE Trojan:
W32/Cryptic.KE is a trojan. The trojan will infect Windows systems.
Upon execution, the trojan drops WinNt32.dll and Pvb38.sys in Windows System folder.
It also drops the following files in the root of C: drive
kyhylwok.exe -1133392630 d.exe d1.exe
The trojan modifies registry at the following locations to load itself during each startup.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinNt32\StartShell HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
The trojan also tries to download other malware to the infected computer. 
|