This Trojan may be dropped by other malware.
File size: 11,648 bytes
File type: SYS
Memory resident: Yes
Initial samples received date: 26 Jan 2012
Arrival Details
This Trojan may be dropped by the following malware:
Autostart Technique
This Trojan registers itself as a system service to ensure its automatic execution at every system startup by adding the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Com32
ImagePath = "%System%\drivers\com32.sys"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Com32
Type = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Com32
Start = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Com32
ErrorControl = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Com32
DisplayName = "Com32"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\FileDisk
ImagePath = "%System%\FileDisk.sys"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\FileDisk
Type = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\FileDisk
Start = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\FileDisk
ErrorControl = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\FileDisk
DisplayName = "FileDisk"
Rootkit Capabilities
This Trojan is used by other malware for its rootkit functionalities.
Connect with us on
| | | |