Infection Channel: Downloaded from the Internet, Dropped by other malware, Infects files
This file infector arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It prepends its codes to target files.
File size: 99,328 bytes
File type: PE
Memory resident: Yes
Initial samples received date: 29 May 2012
Payload: Terminates processes
Arrival Details
This file infector arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This file infector drops the following copies of itself into the affected system:
- %Application Data%\Microsoft\{random}.exe
- %Windows%\xpsp2res.dll
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Windows\Profiles\{user name}\Application Data on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Application Data on Windows NT, and C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000, XP, and Server 2003.. %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
It drops the following non-malicious file:
- {Malware Path}\{random}.docx
File Infection
This file infector infects the following file types:
It prepends its codes to target files.
Process Termination
This file infector terminates the following processes if found running in the affected system's memory:
NOTES:
This file infector avoids infecting files located in all logical drives that are labeled as the following:
- CDROM drives
- Unknown drives
If the file to be infected has the file extension .doc or .docx, it saves the infected file as
{original file name of infected}xcod.scr. It then deletes the original copy of the infected file. Infected files are detected as PE_QUERVAR.A.
Connect with us on
| | | |