TSPY_SKIMER.A
Trojan:Win32/Ligsetrac.D (Microsoft); PWS-BoldDie (McAfee); Trojan.Skimer (Symantec); Trojan.Win32.ExplorerHijack (Sunbelt); Trojan.Skimer.A (FSecure)
Windows
Threat Type: Spyware
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
78,848 bytes
EXE
No
09 Feb 2013
Arrival Details
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other System Modifications
This spyware deletes the following files:
- %Windows%\lsass.exe
- %Windows%\Prefetch
(Note: %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)
Dropping Routine
This spyware drops the following files:
- %Windows%\greenstone.bmp:redstone.bmp
- %Windows%\greenstone.bmp:bluestone.bmp
(Note: %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)