TROJ_OFICLA.AG
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan bears the file icons of certain applications to avoid easy detection and consequent removal.
It deletes itself after execution.
TECHNICAL DETAILS
38,400 bytes
PE
No
11 Sep 2010
Installation
This Trojan bears the file icons of the following applications:
- Microsoft Excel
Other System Modifications
This Trojan adds the following registry keys:
HKEY_CLASSES_ROOT\idid
It modifies the following registry key(s)/entry(ies) as part of its installation routine:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Winlogon
Shell = "Explorer.exe rundll32.exe yise.ero mpgyjp"
(Note: The default value data of the said registry entry is "Explorer.exe".)
Dropping Routine
This Trojan drops the following files:
- %System%\yise.ero - detected as TROJ_DLOADR.SMVE
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Other Details
This Trojan deletes itself after execution.