Technical Details
Payload
Removal instructions
Technical Details
This Trojan program is designed to steal confidential user data. It harvests user names and passwords to a range of services and programs, and incorporates an SMTP server.
The Trojan is a Windows PE EXE file, written in C++, and is 58410 bytes in size.
Once launched, the Trojan copies itself to the Windows root directory under the executable file's original name:
%Windir%\<original Trojan name>.exe
The original executable file is then deleted.
The Trojan registers this file in the system registry to ensure that the Trojan file will be launched each time Windows is rebooted on the victim machine.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"putil" = "%Windir%\<original Trojan name>.exe"
The Task Manager will display the Trojan as a process called <original Trojan name>.
Payload
The Trojan scans the following branches of the system registry, and attempts to harvest passwords which have been saved in the associated programs.
[HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander]
[HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander]
[HKEY_LOCAL_MACHINE\Software\Ghisler]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\&RQ]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trillian]
[HKEY_LOCAL_MACHINE\Software\Mirabilis\ICQ\DefaultPrefs]
[HKEY_LOCAL_MACHINE\Software\Mirabilis\ICQ]
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\Software\Mirabilis]
[HKEY_LOCAL_MACHINE\Software\Miranda]
[HKEY_USERS\.Default\Software\Far\Plugins\FTP\Hosts]
[HKEY_USERS\.Default\Software\Far\Plugins\FTP]
[HKEY_USERS\.Default\Software\Far\Plugins]
[HKEY_USERS\.Default\Software\Far]
[HKEY_USERS\.Default\Software\Ghisler\Total Commander]
[HKEY_USERS\.Default\Software\Ghisler\Windows Commander]
[HKEY_USERS\.Default\Software\Microsoft\Internet Account Manager\Accounts]
[HKEY_USERS\.Default\Software\Microsoft\Internet Account Manager]
[HKEY_USERS\.Default\Software\Mirabilis\ICQ\DefaultPrefs]
[HKEY_USERS\.Default\Software\Mirabilis\ICQ\NewOwners]
[HKEY_USERS\.Default\Software\Mirabilis\ICQ\NewOwners]
[HKEY_USERS\.Default\Software\Mirabilis\ICQ]
[HKEY_USERS\.Default\Software\Mirabilis]
[HKEY_USERS\.Default\Software\RIT\The Bat!]
[HKEY_USERS\.Default\Software\RIT]
The harvested information is periodically sent to a remote malicious user's email address.
Removal instructions
Äëÿ ðóÞíîãî óäàëåíèÿ ïðîãðàììû ñëåäóåò âûïîëíèòü ñëåäóþùèå äåéñòâèÿ:
- In Task Manager, terminate the process with the Trojan name
- Delete the Trojan file from the Windows root directory
- Delete the following system registry keys
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"putil"="%Windir%\<original Trojan name>.exe"
- Perform a full scan of your computer (download a trial version of Kaspersky Anti-Virus).
Summary
Technical details
The main file is a Windows application (PE EXE file).
File size of 58410 bytes.
Installation
Copies itself once launched
Creates files on the victim machine
Ensures
Using the system registry, system services or special system files, the program can launch itself or launch the creation of its files every time the Windows OS is subsequently booted autorun of installed files:
by writing to autorun keys in the system registry
Malicious activity
Steals confidential user information from
A malicious program designed to steal accounts (login and password) from instant messaging clients pagers (e.g., ICQ, MSN Messenger, Yahoo Pager, QQ, Skype, etc.). The information is sent to a cybercriminal via email, ftp, the web or other methods. The stolen accounts can be sold or used to spread other malicious programs.
Read more details here: http://www.viruslist.com/en/analysis?pubid=204792005the following internet pagers:
Steals the following confidential user information:
Others
- FTP accounts from Total Commander
Connects to specific Internet addresses
Checks for Dial-Up connections on the infected computer
Other activities
Runs specific files (commands)