This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It deletes the initially executed copy of itself.
File size: 44,032 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 02 Feb 2012
Payload: Downloads files
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following copies of itself into the affected system:
- %User Profile%\Application Data\170316.exe
(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
It adds the following processes:
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Policies\
Explorer\Run
Winternals = "%User Profile%\Application Data\170316.exe"
Download Routine
This Trojan accesses the following websites to download files:
- http://www.{BLOCKED}8483825.ru/hhh/index.php - detected as TSPY_SPCESEND.A
- http://www.{BLOCKED}tarlogic.com/forum/Themes/core/images/topic/1.exe - detected as TROJ_FAKEAV.FQP
- http://www.{BLOCKED}tarlogic.com/forum/Themes/core/images/topic/offf.exe - detected as TSPY_ZBOT.IGK
- http://www.{BLOCKED}rautos.ca/img/1.exe - detected as TROJ_FAKEAV.FQO
- http://{BLOCKED}udo.com/images/1.exe - inaccessible
- http://{BLOCKED}udo.com/images/rec.exe - inaccessible
Other Details
This Trojan deletes the initially executed copy of itself
Connect with us on
| | | |