Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

TROJANDOWNLOADER.MUTANT.JEW

 

 

Name:

TrojanDownloader.Mutant.jew

Added:

December 22, 2011

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Malware problems?   We can help.  Free Removal Tools.

 

 

Description:

 

When TrojanDownloader.Mutant.jew is executed, it performs the following activities:

After execution, it drops the following files:

%Appdata%\0ufx5kllao.exe
%temp%\cdfss
%temp%\sdn4573.tmp
%temp%\sdn8365.tmp
%temp%\sdn94C.tmp
%System%\drivers\wcscd.sys
%Windir%\Temp\sdn442B.tmp
%Windir%\Temp\sdn8757.tmp


It modifies/creates the following registry entries:

0ufx5kllao = "%Appdata%\0ufx5kllao.exe"
HKU\\Software\Microsoft\Windows\CurrentVersion\Run

ImagePath = "%System%\drivers\wcscd.sys"
HKLM\System\CurrentControlSet\Services\wcscd

ImagePath = "%temp%\cdfss"
HKLM\System\CurrentControlSet\Services\cdfss
 

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4