Home→Descriptions→Trojan.Win32.VB.aeke
| Detected | Apr 26 2010 07:05 GMT |
| Released | Apr 26 2010 17:01 GMT |
| Published | May 19 2010 12:05 GMT |
This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 352 256 bytes in size. It is written in Visual Basic.
When launching, the Trojan copies its executable file to the current user's temporary directory under the name:
%Temp%\geurge.exeIn order to ensure that the Trojan is launched automatically each time the system is rebooted, the Trojan adds a link to its copy to the system registry autorun key:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "ewrgetuj"="%Temp%\geurge.exe"The Trojan then creates a batch file in the root directory of the "C:\" drive, launches this file, and ceases running. The batch file deletes both the original Trojan file and itself.
A copy of the Trojan is launched and checks for the presence of the following files and folders:
%AllUsersProfile%\Desktop\World of Warcraft.lnk %AllUsersProfile%\Desktop\wow.lnk %AllUsersProfile%\Application Data\Blizzard %AllUsersProfile%\Start Menu\Programs\World of Warcraft %ProgramFiles%\World of Warcraft %ProgramFiles%\Common Files\Blizzard Entertainment %ProgramFiles%\World of Warcraft Trial %ProgramFiles%\World of Warcraft %HomePath%\Desktop\World of Warcraft %HomePath%\My Documents\World of Warcraft %HomePath%\My Documents\wow c:\World of Warcraft c:\game\World of Warcraft c:\games\World of Warcraft c:\games\Wow c:\game\Wow c:\Wow c:\World of Warcraft Trial c:\game\World of Warcraft Trial c:\games\World of Warcraft Trial c:\WOW Atlantic c:\games\WOW Atlantic c:\game\WOW AtlanticIt obtains a list of all the user's shortcuts:
%AllUsersProfile%\Desktop\*.lnk %HomePath%\Desktop\*.lnkThen the Trojan gathers information from the files using the following masks:
%HomePath%\Cookies\*.txt %AllU\sersProfile%\Application Data\Microsoft\Network\ Connections\Pbk\*.pbk %System%\Ras\*.pbk %AppData%\Microsoft\Network\Connections\Pbk\*.pbkThe Trojan establishes network communication with the following host, to which it sends the information it has gathered:
config.instal**orm.comThe Trojan may also download a file from this link:
http://122.224.*.48/g.txt?t=0.2316616At the time of writing, this link was inactive.
If your computer does not have an antivirus, and is infected by this malicious program, follow the instructions below to delete it:
%Temp%\geurge.exe
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "ewrgetuj"="%Temp%\geurge.exe"
This type of behaviour covers malicious programs that delete, block, modify, or copy data, disrupt computer or network performance, but which cannot be classified under any of the behaviours identified above.
This classification also covers “multipurpose” Trojan programs, i.e. those that are capable of conducting several actions at once and which demonstrate several Trojan behaviours in a single program. This means they cannot be indisputably classified as having any single behaviour.
Trojan.