TROJ_INJECT.UB
October 09, 2012
PLATFORM:
Windows 2000, Windows XP, Windows Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan drops certain files as part of its installation routine. It modifies the certain registry entries.
TECHNICAL DETAILS
File Size: 8,192 bytes
File Type: EXE
Memory Resident: Yes
Initial Samples Received Date: 08 Apr 2009
Installation
This Trojan drops the following files:
- %User Temp%\123.info
- %User Temp%\shell32.dll
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Other System Modifications
This Trojan modifies the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{35CEC8A3-2BE6-11D2-8773-92E220524153}\InprocServer32
Default = "%User Temp%\shell32.dll"
(Note: The default value data of the said registry entry is %System%\stobject.dll.)