TROJ_DROPPR.YYTB
Trojan.GenericKD.2504284 (F-Secure); Win32:Evo-gen [Susp] (Avast); Win.Trojan.Farfli-3495 (ClamAV)
Windows


Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It modifies the Internet Explorer Zone Settings.
It deletes itself after execution.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- %System Root%\tmp\Assoc.exe
- %System Root%\tmp\Wiseman.exe
- %System Root%\tmp\etel1m223xuv\2d71.txt
(Note: %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.)
Web Browser Home Page and Search Page Modification
This Trojan modifies the Internet Explorer Zone Settings.
Other Details
This Trojan deletes itself after execution.
