This Trojan may be downloaded from remote sites by other malware.
It also has rootkit capabilities, which enables it to hide its processes and files from the user.
File size: Varies
Memory resident: Yes
Initial samples received date: 06 Jan 2011
Payload: Connects to URLs/IPs, Downloads files, Drops files, Modifies system registry
Arrival Details
This Trojan may be downloaded from remote site(s) by the following malware:
Installation
This Trojan drops the following component file(s):
- %WINDOWS%\WinSxS\x86_Microsoft.Windows.Shell.HWEventDetector_6595b64144ccf1df_5.2.2.3_x-ww_5390e909\shsvcs.dll - also detected as RTKT_ZACCESS.SM1
Autostart Technique
This Trojan registers itself as a system service to ensure its automatic execution at every system startup by adding the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{malware filename}
ImagePath = {malware path and file name}.sys
Other System Modifications
This Trojan adds the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Enum\Root\*PNP0296\
0000
Service = {malware file name}
It modifies the following registry entries:
HKEY_CLASSES_ROOT\CLSID\{4FA18276-912A-11D1-AD9B-00C04FD8FDFF}\
InprocServer32
@ = %WINDOWS%\WinSxS\x86_Microsoft.Windows.Shell.HWEventDetector_6595b64144ccf1df_5.2.2.3_x-ww_5390e909\shsvcs.dll
(Note: The default value data of the said registry entry is %System%\wbem\wbemcore.dll.)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{4FA18276-912A-11D1-AD9B-00C04FD8FDFF}\InprocServer32
@ = %WINDOWS%\WinSxS\x86_Microsoft.Windows.Shell.HWEventDetector_6595b64144ccf1df_5.2.2.3_x-ww_5390e909\shsvcs.dll
(Note: The default value data of the said registry entry is %System%\wbem\wbemcore.dll.)
Rootkit Capabilities
This Trojan also has rootkit capabilities, which enables it to hide its processes and files from the user.
Download Routine
This Trojan accesses the following websites to download files:
- http://{BLOCKED}.{BLOCKED}.130.34/{BLOCKED}e.db
It saves the files it downloads using the following names:
- %Windows%\Temp\{random}.tmp
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
Trend Micro detects the dowloaded file as:
Connect with us on
| | | |