Home / malwarePDF  

TrojanDropper:Win32/Kanav.E


First posted on 29 January 2013.
Source: Microsoft

Aliases :

TrojanDropper:Win32/Kanav.E is also known as Trojan.KillProc.21103 (Dr.Web), Trojan.Win32.Alyak (Ikarus), TROJ_ALYAK.SMAE (Trend Micro).

Explanation :



TrojanDropper:Win32/Kanav.E is a trojan that drops other files, often malicious, into your computer.

It may appear on your computer with the same name as a legitimate system file, "lpk.dll". This malware file will exist in parallel with the legitimate file, so that both files can run on your computer.

When it runs, TrojanDropper:Win32/Kanav.E will drop a file names "apple.exe" into the same folder that it it located in, and run this file, which may be detected as TrojanDownloader:Win32/Kanav.F.



Analysis by Stefan Sellmer

Last update 29 January 2013

 

TOP