Infection Channel: Dropped by other malware, Downloaded from the Internet
This Trojan connects to certain URLs to send and receive commands from a remote malicious user. It terminates processes, some of which are related to system security.
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It deletes itself after execution.
File size: 185,856 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 29 Sep 2012
Payload: Drops files, Connects to URLs/IPs, Terminates processes, Compromises system security
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan injects itself into the following processes running in the affected system's memory:
It creates the following folders:
- %Windows%\$NtUninstallKB34902$\2349794393\
- %Windows%\$NtUninstallKB34902$\2349794393\L
- %Windows%\$NtUninstallKB34902$\2349794393\U
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
Other System Modifications
This Trojan deletes the following registry keys:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\BITS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SharedAccess
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\wscsvc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\wuauserv
Dropping Routine
This Trojan drops the following files:
- %Windows%\$NtUninstallKB34902$\2349794393\Desktop.ini - detected as TROJ_SIREFEF.AEL
- %Windows%\$NtUninstallKB34902$\2349794393\U\00000004.@ - detected as TROJ_ZEROA.SM3
- %Windows%\$NtUninstallKB34902$\2349794393\U\00000008.@ - detected as TROJ_DROPR.ZA
- %Windows%\$NtUninstallKB34902$\2349794393\U\000000cb.@ - detected as TROJ_SIREFEF.DAM
- %Windows%\$NtUninstallKB34902$\2349794393\U\80000000.@ - detected as TROJ_ZEROA.SM1
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
Other Details
This Trojan deletes itself after execution.
NOTES:
It accesses the following site to know its location:
- http://{BLOCKED}ling.com/geo/txt/city.php
Connect with us on
| | | |