Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

TROJANDOWNLOADER.FRAUDLOAD.YC

 

 

 

Name:

TrojanDownloader.Fraudload.yc

Added:

January 28, 2011

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Description:

 

When TrojanDownloader.Fraudload.yc is executed, it performs the following activities:

It drops the following files:

%Windir%\inf\stevr.inf
%Windir%\inf\inetsvr.pnf
%Windir%\inf\{Random name}.bat
%Windir%\inf\rstd.bat
%Windir%\inf\jkk.bat
%Windir%\inf\rsed.vbs

It creates the following registry entry:

DisplayName = "Windows Internet Service"
ImagePath = "%SystemRoot%\inf\{Random name}.bat"
HKLM\System\CurrentControlSet\Services\inetsvr

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Malware problems?
We can help.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Evaluate Thirtyseven4 Antivirus Now

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4