| Malware name | Win32.Perlovga.A.1 | | Type | Trojan | | Affected platform | Win32 | | Media-Type | application/executable | | MD5 checksum | 46C731D04513A6BB711D9B29C753077C | | Static file | yes | | Filesize | 31,236 Bytes | Alias names (also known as) | | Webwasher Proactive | Win32.Malware.gen#FSG | | Sophos | W32/Fujacks-I | | McAfee | W32/Fujacks.a | | CA ETrust | Win32/Emerleox.BO |
| | Protection | | Webwasher Anti Malware | 6034.1181.x | | Webwasher Proactive | Database Version: 54 |
| | Propagation | No own spreading routine |
|
Description:
Files
It copies itself to the following location:
• %WINDIR%\xcopy.exe
It copies the following files:
• C:\host.exe into %WINDIR%\svchost.exe
• C:\autorun.inf into %WINDIR%\autorun.inf
It tries to executes the following file:
– Filename:
• %WINDIR%\svchost.exe
File details
Programming language:
The malware program was written in MS Visual C++.
Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.