TROJ_DROPPER.XXTXR
Windows
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- %Windows%\wc98pp.dll
(Note: %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)
Other System Modifications
This Trojan adds the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
PROTOCOLS\Handler\ic32pp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{GUID}\InprocServer32
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{GUID}\InprocServer32
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
5.0\Cache\Extensible Cache\
MSHist012018030720180308
It adds the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
PROTOCOLS\Handler\ic32pp
CLSID = {GUID}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{GUID}\InprocServer32
ThreadingModel = "Apartment"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
Enable = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
Size = "a"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
InitHits = "100"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
Factor = "20"