Selected viruses, spyware, and other threats: sorted alphabetically
Win32/Fusing.BD
|
Short description
Win32/Fusing.BD installs a backdoor that can be controlled remotely.Installation
When executed, the trojan creates the following folder:- %systemdrive%Documents and SettingsLocal User
The following file is dropped into the %systemdrive%Documents and SettingsLocal User folder:
- windmad.dll (117833 B)
The trojan registers itself as a system service using the following filename:
- Microsoft Device Manager
- [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersion
Svchostnetsvcs]
- 6to4
- Ias
- Iprip
- Irmon
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices
%servicename%]
"Type" = "%variable1%" - [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices
%servicename%]
"InstallModule" = "%variable2%" - [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices
%servicename%]
"Description" = "%string%"
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices
%servicename%]
"Type" = "%variable1%" - [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices
%servicename%]
"InstallModule" = "%variable2%" - [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices
%servicename%]
"Description" = "%string%" - [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices
%servicename%Parameters]
"ServiceDll" = "%systemdrive%Documents and SettingsLocal
Userwindmad.dll" - [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices
%servicename%Parameters]
"ServiceMain" = "MyLive"
A string with variable content is used instead of %variable1-2%. The strings written in Chinese language are used instead of %string%.
The trojan deletes the original file.
Other information
The trojan acquires data and commands from a remote computer or the Internet. The trojan contains a list of URLs. The TCP protocol is used.It can execute the following operations:
- update itself to a newer version
- download files from a remote computer and/or the Internet
- run executable files
- iexplore.exe
- winlogon.exe
