TROJ_ETCHFRO.AD
Publish Date: 20 de июня de 2014
a variant of Win32/Etchfro.D trojan (ESET), Troj/Tubs-A (Sophos)
PLATFORM:
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
OVER ALL RISK RATING:
DAMAGE POTENTIAL::
DISTRIBUTION POTENTIAL::
REPORTED INFECTION:
INFORMATION EXPOSURE:
Low
Medium
High
Critical
Threat Type:
Trojan
Destructiveness:
No
Encrypted:
In the wild::
Yes
OVERVIEW
TECHNICAL DETAILS
File size: 91,576 bytes
File type: DLL
INITIAL SAMPLES RECEIVED DATE: 19 июня 2014
Instalación
Infiltra los archivos siguientes:
- {All Users Profile}\Application Data\{random folder name}\{random filename}
- %ProgramData%\{random folder name}\{random filename}
- {Pictures Default Folder}\{random folder name}\{random filename}
- {Music Default Folder}\{random folder name}\{random filename}
- {Favorites Default Folder}\{random folder name}\{random filename}
- {All Users Profile}\Application Data\Windows NT\wp.dat
- {All Users Profile}\Application Data\Windows NT\config.dat
- {All Users Profile}\Application Data\Windows NT\del.bat
- %ProgramData%\Windows NT\wp.dat
- %ProgramData%\Windows NT\config.dat
- %ProgramData%\Windows NT\del.bat