Infection Channel: Dropped by other malware
This malware connects to a certain site to inform a remote user of its installation and send information such as username and hostname.
This Trojan may be dropped by other malware.
File size: 32,768 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 20 Mar 2012
Payload: Connects to URLs/IPs
Arrival Details
This Trojan may be dropped by the following malware:
Installation
This Trojan drops the following copies of itself into the affected system:
- %System%\2019\svchost .exe
- %User Startup%\wuauclt.exe
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.. %User Startup% is the current user's Startup folder, which is usually C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup on Windows NT, and C:\Documents and Settings\{User name}\Start Menu\Programs\Startup.)
It creates the following folders:
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Other System Modifications
This Trojan modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\
Shell Folders
Startup = "%System%\2019"
(Note: The default value data of the said registry entry is %User Startup%.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\
User Shell Folders
Startup = "%System%\2019"
(Note: The default value data of the said registry entry is %User Startup%.)
NOTES:
It copies the files in the %User Startup% directory to its created folder %System%\2019.
It connects to the following site to inform a remote user of its installation and send information such as username and hostname:
Connect with us on
| | | |