Threat Database Trojans Trojan.Virut.IC

Trojan.Virut.IC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,358
Threat Level: 80 % (High)
Infected Computers: 117
First Seen: May 27, 2021
Last Seen: March 1, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Virut.IC
Signature status: No Signature

Known Samples

MD5: aa14b27495c0e1509c98e380dc8db998
SHA1: 2c8676e8745e0514c6b340423d69bb02c5920a5f
SHA256: A027228A94879FF5BB8D050617C38165A8DE1ED41736F0D5894F246B0B2B5736
File Size: 54.27 KB, 54272 bytes
MD5: 104823cda40889b1da51c8dee1300227
SHA1: db80ee824c23fd54028d1b18f04d86e24aca3c16
SHA256: EEBE99C395F23E3C79B77236D6E7D8151F055DC8BAB20C18CB436BE842E61BAC
File Size: 44.03 KB, 44032 bytes
MD5: 12d165399521228781f21a1938948bfd
SHA1: c693eb72b8e5b716795bdd39efada45369ddbd27
SHA256: D380E6C623F701760B24527003D017826874614A85E82F906125F2375B399903
File Size: 54.27 KB, 54272 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description
  • AppID Certificate Store Verification Task
  • Userinit Logon Application
File Version
  • 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
  • 6.1.7601.17514 (win7sp1_rtm.101119-1850)
Internal Name
  • AppIDCertstoreCheck.exe
  • userinit
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename
  • AppIDCertstoreCheck.exe
  • USERINIT.EXE
Product Name Microsoft® Windows® Operating System
Product Version
  • 6.1.7601.24545
  • 6.1.7601.17514

File Traits

  • 2+ executable sections
  • HighEntropy
  • ntdll
  • x86

Block Information

Total Blocks: 171
Potentially Malicious Blocks: 11
Whitelisted Blocks: 153
Unknown Blocks: 7

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 ? 0 ? x x x x ? ? ? 0 x x x x x ? ? x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Virut.I
  • Virut.IB
  • Virut.IE
  • Virut.IF

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list::c:\users\user\downloads\2c8676e8745e0514c6b340423d69bb02c5920a5f_0000054272 c:\users\user\downloads\2c8676e8745e0514c6b340423d69bb02c5920a5f_0000054272:*:enabled:@shell32.dll,-1 RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list::c:\users\user\downloads\db80ee824c23fd54028d1b18f04d86e24aca3c16_0000044032 c:\users\user\downloads\db80ee824c23fd54028d1b18f04d86e24aca3c16_0000044032:*:enabled:@shell32.dll,-1 RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list::c:\users\user\downloads\c693eb72b8e5b716795bdd39efada45369ddbd27_0000054272 c:\users\user\downloads\c693eb72b8e5b716795bdd39efada45369ddbd27_0000054272:*:enabled:@shell32.dll,-1 RegNtPreCreateKey

Trending

Most Viewed

Loading...