Selected viruses, spyware, and other threats: sorted alphabetically
Win32/Olmarik.XG
|
Short description
The trojan contains a backdoor. It can be controlled remotely. It uses techniques common for rootkits.Installation
When executed, the trojan creates the following files:- %temp%%random1%.tmp (31232 B)
- %temp%%random2%.tmp (89600 B)
The following files are modified:
- %system%drivers*.sys
- fvevol.sys
- ksecdd.sys
- win32k.sys
- pci.sys
The size of the inserted code is 396 B.
The following Registry entries are created:
- [HKEY_LOCAL_MACHINESystemCurrentControlSetServices
%random3%]
"ImagePath" = "%temp%%random1%.tmp"
"Type" = 1
The trojan may create and run a new thread with its own program code within any running process.
Information stealing
The trojan collects the following information:- a list of recently visited URLs
- operating system version
Other information
The trojan acquires data and commands from a remote computer or the Internet.The trojan contains a list of (18) URLs. The HTTP, HTTPS protocol is used.
It can execute the following operations:
- download files from a remote computer and/or the Internet
- run executable files
- [HKEY_LOCAL_MACHINESoftwareMicrosoftInternet Explorer
MainFeatureControlFEATURE_BROWSER_EMULATION]
"svchost.exe" = 8000
- [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
Internet Settings]
"MaxHttpRedirects" = 8000 - [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
Internet Settings]
"EnableHttp1_1" = 1
- [HKEY_LOCAL_MACHINESoftwareMicrosoftInternet Explorer
MainFeatureControlFEATURE_BROWSER_EMULATION]
"svchost.exe" = 8000
- [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
Internet Settings]
"MaxHttpRedirects" = 8000 - [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
Internet Settings]
"EnableHttp1_1" = 1 - [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
Internet SettingsZones3]
"CurrentLevel" = 0
"1601" = 0
"1400" = 0
