Home Malware Programs Trojans VirTool:MSIL/Injector.AH

VirTool:MSIL/Injector.AH

Posted: April 11, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 14
First Seen: April 11, 2012
Last Seen: August 6, 2019
OS(es) Affected: Windows

VirTool:MSIL/Injector.AH is a Windows rootkit Trojan, which can allow Simple Mail Transfer Protocol (SMTP) to distribute malicious components. VirTool:MSIL/Injector.AH hides itself and, therefore, it difficult to detect and remove from the affected computer by many security applications. VirTool:MSIL/Injector.AH affects security of your personal data. VirTool:MSIL/Injector.AH Trojan can gather your user names, passwords and other private details and then sends them to remote servers. VirTool:MSIL/Injector.AH can record keyboard inputs and control screen content. VirTool:MSIL/Injector.AH can inject a malicious code into the Windows operating system's startup programs, create files, corrupt processes, drop and delete Registry components, run operations found in the temporary folders, and remove privileges to important Windows applications, such as Registry Editor, Task Manager and Windows Security Center, all of which could help to remove VirTool:MSIL/Injector.AH from the infected computer.

Aliases

Dropper.Generic.BVZA [AVG]W32/Palevo.VTV!worm.p2p [Fortinet]Backdoor.Win32.EggDrop [Ikarus]Win32/Palevo.worm.214016.B [AhnLab-V3]Backdoor.Win32.EggDrop!IK [a-squared]Worm/Win32.Palevo.gen [Antiy-AVL]Mal/Resdro-A [Sophos]Worm.Palevo.vtv [McAfee-GW-Edition]WORM_PALEVO.BW [TrendMicro]Worm/Palevo.vtv [AntiVir]BackDoor.IRC.Bot.223 [DrWeb]Heur.Suspicious [Comodo]Worm.P2P.Palevo.BT [BitDefender]P2P-Worm.Win32.Palevo.vtv [Kaspersky]Worm.Palevo-6855 [ClamAV]
More aliases (61)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\RECYCLER\S-1-5-21-4849848699-8487205352-732294630-6424\mwau.exe File name: mwau.exe
Size: 214.01 KB (214016 bytes)
MD5: 261531667d71fc99247225ea99b6253d
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-4849848699-8487205352-732294630-6424
Group: Malware file
Last Updated: April 17, 2012
%PROGRAMFILES%\Ultima\ArtecMedia\iScheduleRec.exe File name: iScheduleRec.exe
Size: 126.97 KB (126976 bytes)
MD5: 82d8f386d363e9b22ee4ce9d8673f359
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Ultima\ArtecMedia
Group: Malware file
Last Updated: April 12, 2012
Loading...