TROJ_ETCHFRO.AD
a variant of Win32/Etchfro.D trojan (ESET), Troj/Tubs-A (Sophos)
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan may arrive bundled with malware packages as a malware component. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Arrival Details
This Trojan may arrive bundled with malware packages as a malware component.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- {All Users Profile}\Application Data\{random folder name}\{random filename}
- %ProgramData%\{random folder name}\{random filename}
- {Pictures Default Folder}\{random folder name}\{random filename}
- {Music Default Folder}\{random folder name}\{random filename}
- {Favorites Default Folder}\{random folder name}\{random filename}
- {All Users Profile}\Application Data\Windows NT\wp.dat
- {All Users Profile}\Application Data\Windows NT\config.dat
- {All Users Profile}\Application Data\Windows NT\del.bat
- %ProgramData%\Windows NT\wp.dat
- %ProgramData%\Windows NT\config.dat
- %ProgramData%\Windows NT\del.bat
(Note: %ProgramData% is a version of the Program Files folder where any user on a multi-user computer can make changes to programs. This is usually C:\ProgramData in Windows Vista and 7, or C:\Program Files on Windows 2000, XP (32-bit), and Server 2003, or C:\Program Files (x86) on Windows XP (64-bit).)