KV_XP.EXE – Trojan Generic

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

KV_XP.EXE – Trojan Generic removal

FileMD5Virus Alias
KV_XP.EXE 77e52b42f52118312f767e49ad1a7b81 Trojan Generic
KV_XP.EXE 77e52b42f52118312f767e49ad1a7b81 Trojan Downloader
KV_XP.EXE 77e52b42f52118312f767e49ad1a7b81 Trojan Agent

KV_XP.EXE size: 39936 bytes
KV_XP.EXE hash: 77E52B42F52118312F767E49AD1A7B81

Created files:

%SysDir%\kv_xp.exe
%WinDir%\_hook.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\WS2IFSL\Type: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\Start: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\WS2IFSL\DisplayName: Windows Socket 2.0 Non-IFS Service Provider Support Environment
HKLM\System\CurrentControlSet\Services\WS2IFSL\ImagePath: \SystemRoot\System32\drivers\ws2ifsl.sys

Detected by UnHackMe:

KV_XP.EXE
Default location: %SYSDIR%\KV_XP.EXE

Dropper information:
MD5: 18074ec0d9f38d64954d6a097f5a0847
File size: 525312 bytes

Leave a Reply