Infection Channel: Infects files
Trend Micro has received multiple samples of this malware from multiple, independent sources, including customer reports and internal sources. These indicate that this file infector poses a high risk to users due to the increased possibility of infection.
To get a one-glance comprehensive view of the behavior of this File infector, refer to the Threat Diagram shown below.

This file infector executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
File size: Varies
File type: PE
Memory resident: Yes
Initial samples received date: 06 Sep 2010
Payload: Downloads files
File Infection
This is the Trend Micro detection for files infected by:
Download Routine
This file infector accesses the following websites to download files:
- http://{pseudorandom alpha characters}.biz/forum/
- http://{pseudorandom alpha characters}.org/forum/
- http://{pseudorandom alpha characters}.info/forum/
- http://{pseudorandom alpha characters}.net/forum/
- http://{pseudorandom alpha characters}.com/forum/
It saves the files it downloads using the following names:
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
Other Details
This file infector does the following:
- Generates a list of 800 domain names at every execution
- Infected files do not have the capability to infect other files
- Capable of generating pseudorandom alpha characters using a randomizing function which is computed from the current UTC system date and time
Connect with us on
| | | |