TROJ_KRYPTO.SMIU
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It also has rootkit capabilities, which enables it to hide its processes and files from the user.
It modifies the Internet Explorer Zone Settings.
TECHNICAL DETAILS
175,616 bytes
EXE
Yes
30 Jul 2011
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following component file(s):
- %System Root%\Recycle.Bin\{random name}
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It drops the following copies of itself into the affected system:
- %System Root%\Recycle.Bin\{random filename}.exe
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It creates the following folders:
- %System Root%\Recycle.Bin
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It terminates the execution of the copy it initially executed and executes the copy it drops instead.
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
{random} = "%System Root%\Recycle.Bin\{random filename}.exe /q"
Other System Modifications
This Trojan adds the following registry keys:
HKEY_CURRENT_USER\Software\Microsoft Windows
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Recovery
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\PhishingFilter
It adds the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft Windows
{random value} = "{hex values}"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\PhishingFilter
EnabledV8 = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\PhishingFilter
ShownServiceDownBalloon = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Recovery
ClearBrowsingHistoryOnExit = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
WarnOnPostRedirect = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
WarnOnIntranet = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
GlobalUserOffline = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
ProxyHttp1.1 = "1"
It modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
WarnOnPost = "0"
(Note: The default value data of the said registry entry is 1.)
Rootkit Capabilities
This Trojan also has rootkit capabilities, which enables it to hide its processes and files from the user.
Web Browser Home Page and Search Page Modification
This Trojan modifies the Internet Explorer Zone Settings.