TROJ_OTORUN.TICOGAU
Windows
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
45,000 bytes
INF
No
05 Apr 2013
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Propagation
The said .INF file contains the following strings:
[autorun]
;{garbage}
open=Updates\Drivers\System.exe
;{garbage}
icon=%SystemRoot%\system32\SHELL32.dll,7
;{garbage}
action=Open folder to view files
;{garbage}
shell\open=Open
;{garbage}
shell\open\Command=Updates\Drivers\System.exe
;{garbage}
UseAutoPlay = 1
;{garbage}
shell\explore\Command=Updates\Drivers\System.exe
;{garbage}
Other Details
This Trojan does the following:
- This Trojan automatically executes the following files when a user opens a drive:
- Updates\Drivers\System.exe