| Malware name | Trojan.VB.dnz | | Type | Trojan | | Affected platform | Win32 | | Media-Type | application/executable | | MD5 checksum | D90E680564229D86E6311EF9A11CDA8C | | Static file | yes | | Filesize | 86,016 Bytes | Alias names (also known as) | | Sophos | Mal/VB-F | | McAfee | Montague | | CA ETrust | Win32/Moriogu.A |
| | Side effects | Registry modification | | Propagation | No own spreading routine |
|
Description:
Files
It copies itself to the following locations:
• %SYSDIR%\Win2x.exe
• %SYSDIR%\save.exe
The following file is created:
– Non malicious file:
• %SYSDIR%\dll.sys
Registry
The following registry keys are added in order to run the processes after reboot:
– [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
• Win2x="%SYSDIR%\Win2x.exe"
– [HKLM\SYSTEM\ControlSet001\Services\Win2x]
• Start=dword:00000002
• Type=dword:00000110
• ErrorControl=dword:00000001
• ObjectName="LocalSystem"
• ImagePath=%SYSDIR%\save.exe
File details
Programming language:
The malware program was written in Visual Basic.