TROJ_AGENT.WTHI
October 08, 2012
PLATFORM:
Windows 2000, XP, Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
TECHNICAL DETAILS
File Size: Varies
File Type: EXE
Memory Resident: Yes
Initial Samples Received Date: 21 Sep 2010
Installation
This Trojan stays memory-resident by injecting codes into the following processes:
- csrss.exe
Other System Modifications
This Trojan adds the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Control\Session Manager
PendingFileRenameOperations = "\??\{malware path and file name}"