This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 307,200 bytes
File type: EXE
Memory resident: No
Initial samples received date: 15 Nov 2012
Arrival Details
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other System Modifications
This spyware deletes the following files:
- %Windows%\Microsoft.NET\Framework\v2.0.50727\config\security.config.cch.1872.1199515
- %Windows%\Microsoft.NET\Framework\v2.0.50727\config\enterprisesec.config.cch.1872.1199515
- %User Profile%\v2.0.50727.42\security.config.cch.1872.1199625
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.. %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
Dropping Routine
This spyware drops the following files:
This report is generated via an automated analysis system.
Connect with us on
| | | |