Analysis by: Christopher Daniel So

ALIASES:

Win32/Skipwuser.A;BAT.Netstop.Trojan;Trojan.Win32.MicroFake.p;Application.DisableWUpdate.A

 PLATFORM:

Windows 2000, XP, Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  TECHNICAL DETAILS

File Size: 8,704 bytes
File Type: EXE
Memory Resident: No
Initial Samples Received Date: 22 Jul 2010

Other Details

This Trojan does the following:

  • It opens http://windowsupdate.microsoft.com in Internet Explorer to install the latest updates. It then stops the Windows Update service and disables the Windows Update and Background Intelligent Transfer Services (BITS).