Analysis by: Jennifer Gumban

 PLATFORM:

Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

 OVERALL RISK RATING:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It modifies the Internet Explorer Zone Settings.

  TECHNICAL DETAILS

Tamaño del archivo 362,255 bytes
Tipo de archivo EXE
Fecha de recepción de las muestras iniciales 03 Aug 2012

Arrival Details

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This Trojan drops a copy of itself in the following folders using different file names:

  • %System%\lkavs3d.exe
  • %System%\netstsys.exe
  • %System%\rdatdll5.exe
  • %System%\wndscsy.exe

(Note: %System% is the Windows system folder, which is usually C:\Windows\System32.)

Other System Modifications

This Trojan modifies the following registry entries:

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Policies\
Explorer
NoFolderOptions = "1"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Policies\
System
DisableRegistryTools = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Winlogon
Settings2 = "rdatdll5.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Winlogon
Winlogo Startupc = "explorer.exe rdatdll5.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\RunOnce
System Servicet = "rdatdll5.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\policies\
Explorer\Run
Options3 = "r"

Web Browser Home Page and Search Page Modification

This Trojan modifies the Internet Explorer Zone Settings.

NOTES:

This Trojan changes the attributes of the dropped files to Hidden.