Infection Channel: Dropped by other malware
This spyware may be dropped by other malware.
It connects to certain websites to send and receive information.
File size: 46,304 bytes
File type: PE
Memory resident: Yes
Initial samples received date: 12 Apr 2012
Arrival Details
This spyware may be dropped by the following malware:
- TROJ_ARTIEF.FU
- TROJ_MDROP.GDL
Installation
This spyware drops the following files:
- %System Root%\Documents and Settings\All Users\Application Data\Windows NT\NtHelpConfig.log - encrypted component
- %System Root%\Documents and Settings\All Users\Application Data\Windows NT\NtHelpIndex.sbr - encrypted component
- %System Root%\Documents and Settings\All Users\Application Data\Windows NT\NtHelpKey.cfg - encrypted component
- %System Root%\Documents and Settings\All Users\Application Data\Windows NT\NtHelpKey.sbr - encrypted component
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It drops the following component file(s):
- %System Root%\WINDOWS\fxsst.dll - also detected as TSPY_GEDDEL.EVL
- %System Root%\Documents and Settings\All Users\Application Data\Windows NT\common.cfg - encrypted binary component. When decrypted, it is also detected as TSPY_GEDDEL.EVL
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It adds the following processes:
It creates the following folders:
- %System Root%\Documents and Settings\All Users\Application Data\Windows NT
- %System Root%\Documents and Settings\All Users\Application Data\Windows NT\Support
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It injects itself into the following processes as part of its memory residency routine:
Process Termination
This spyware terminates processes or services that contain any of the following strings if found running in the affected system's memory:
- ccsvchst
- sfctlcom
- ravmond
- mpmon
- twister
- vsmon
- Mupage
- KSafeSvc
- avguard.exe
Other Details
This spyware connects to the following website to send and receive information:
- 1.test.{BLOCKED}2.org.cn
- 2.test.{BLOCKED}2.org.cn
- 3.test.{BLOCKED}2.org.cn
- 4.test.{BLOCKED}2.org.cn
- 123ewqasdcxz.{BLOCKED}p.net
- hoop-america.{BLOCKED}p.net
NOTES:
This spyware logs open windows and user keystrokers to steal information. It then saves the stolen information in the file %System Root%\Documents and Settings\All Users\Application Data\Windows NT\Support\{numbers}.kb.
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
Connect with us on
| | | |