Home Malware Programs Trojans Trojan.Loskad

Trojan.Loskad

Posted: July 7, 2017

Threat Metric

Ranking: 4,031
Threat Level: 8/10
Infected PCs: 71,322
First Seen: July 7, 2017
Last Seen: October 17, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\agu0OP36Pw3g.exe File name: agu0OP36Pw3g.exe
Size: 2.38 MB (2384920 bytes)
MD5: d3c6259a787a0fae941ef80cc49c32bb
Detection count: 304
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: July 19, 2017
file.exe File name: file.exe
Size: 1.56 MB (1562008 bytes)
MD5: f14e2c7945822302a0e5351dc5558e43
Detection count: 88
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 30, 2017
%APPDATA%\Microsoft\msi.exe File name: msi.exe
Size: 2.61 MB (2618360 bytes)
MD5: bb45b956916334881dfc67bffcd16feb
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft
Group: Malware file
Last Updated: July 19, 2017
C:\Windows\Microsoft\svchost.exe.update.exe File name: svchost.exe.update.exe
Size: 1.26 MB (1264616 bytes)
MD5: 1cc60d6bb43977f84dd91987092b6d2a
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Microsoft\svchost.exe.update.exe
Group: Malware file
Last Updated: August 29, 2021

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\curl\curl_7_54.exe%APPDATA%\Microsoft\msi.exe%APPDATA%\wget\wget.exe%APPDATA%\wget\wget_1_19_4.exe%LOCALAPPDATA%\Deployment\Deploymentz.exe%LOCALAPPDATA%\Google\Googlez.exe%WINDIR%\Microsoft\svchost.exe%WINDIR%\Microsoft\svchost.exe.exeHKEY..\..\..\..{RegistryKeys}Software\GASTATSoftware\iesgSoftware\nageincSYSTEM\ControlSet001\services\SvcHost Service HostSYSTEM\ControlSet002\services\SvcHost Service HostSYSTEM\CurrentControlSet\services\SvcHost Service Host
Loading...