Besoin d’aide ? Fais appel à la communauté ou embauche un spécialiste.
Aller à Avira Answers
Date discovered:15/05/2013
In the wild:Yes
Reported Infections:Medium to high
Distribution Potential:Low
Damage Potential:Low to medium
Static file:Yes
File size:68.608 Bytes
MD5 checksum:EA4C997FE1A5BBCA8895A75DC937B402
VDF version:
IVDF version:

 General Method of propagation:
   • No own spreading routine

   •  Kaspersky: Trojan-Ransom.Win32.Blocker.beqq
   •  Bitdefender: Trojan.Gamarue.AV
   •  Eset: Win32/TrojanDownloader.Wauchos.I
   •  GData: Trojan.Gamarue.AV

Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003
   • Windows Vista
   • Windows Server 2008
   • Windows 7

Side effects:
   • Drops a malicious file
   • Registry modification

 Files It copies itself to the following location:
   • %ALLUSERSPROFILE%\svchost.exe

 Registry The following registry key is added in order to run the process after reboot:

– HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
   • "SunJavaUpdateSched"="%ALLUSERSPROFILE%\svchost.exe"

Description insérée par Eric Burk le mercredi 15 mai 2013
Description mise à jour par Eric Burk le mercredi 15 mai 2013

Retour . . . .