This Trojan may be unknowingly downloaded by a user while visiting malicious websites. It may be dropped by other malware.
File size: 110,592 bytes
File type: EXE
Memory resident: No
Initial samples received date: 22 Dec 2011
Payload: Drops files
Arrival Details
This Trojan may be unknowingly downloaded by a user while visiting malicious websites.
It may be dropped by the following malware:
Installation
This Trojan drops the following files:
- %Windows%\ime\wmimachine2.dll - detected by Trend Micro as BKDR_PPOINTER.SM
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
Its DLL component is injected to the following process(es):
Autostart Technique
This Trojan registers its dropped component as a system service to ensure its automatic execution at every system startup. It does this by creating the following registry keys:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{first netsvcs}
Type = "dword:00000020"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{first netsvcs}
Start = "2"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{first netsvcs}
ErrorControl = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{first netsvcs}
ImagePath = "%SystemRoot%\system32\svchost.exe -k netsvcs"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{first netsvcs}
DisplayName = ".NET Runtime Optimization Service v2.086521.BackUp_X86"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{first netsvcs}
ObjectName = "LocalSystem"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{first netsvcs}
Description = "Microsoft .NET Framework NGEN"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\{first netsvcs}\Parameters
ServiceDll = "%Windows%\ime\wmimachine2.dll"
NOTES:
It queries the following registry and checks the first value that does not have a service installed:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs
Once found, it uses this name as its DLL component's service name. Usually, the first it finds is:
Connect with us on
| | | |