This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It disables Task Manager, Registry Editor, and Folder Options.
File size: 103,936 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 05 Nov 2011
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Autostart Technique
This Trojan modifies the following registry entries to ensure it automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Winlogon
Shell = "{malware path and file name}.exe"
(Note: The default value data of the said registry entry is Explorer.exe.)
Other System Modifications
This Trojan adds the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Outlook Express
palo = "1117568389"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Outlook Express
mynum = "89853366153"
It modifies the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot
AlternateShell = "{malware path and file name}.exe"
(Note: The default value data of the said registry entry is cmd.exe.)
It creates the following registry entry(ies) to disable Task Manager, Registry Tools and Folder Options:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\policies\
system
DisableTaskMgr = 1
This report is generated via an automated analysis system.
Social Media Links
Connect with us on
| | | |