Analysis by: Sabrina Lei Sioting

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This Trojan deletes itself after execution.

  TECHNICAL DETAILS

Tamaño del archivo 232,464 bytes
Tipo de archivo EXE
Residente en memoria No
Fecha de recepción de las muestras iniciales 14 Jun 2011

Installation

This Trojan drops the following files:

  • %User Profile%\Application Data\DatacardService\DCService.exe
  • %User Temp%\svchost.exe
  • %Program Files%\Common Files\DatacardService\DCService.exe

(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.. %Program Files% is the default Program Files folder, usually C:\Program Files.)

It creates the following folders:

  • %User Profile%\Application Data\DatacardService
  • %Program Files%\Common Files\DatacardService

(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.. %Program Files% is the default Program Files folder, usually C:\Program Files.)

Other Details

This Trojan deletes itself after execution.