Home Malware Programs Trojans Infostealer.Limitail

Infostealer.Limitail

Posted: September 11, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 5,621
First Seen: September 11, 2012
Last Seen: August 17, 2022
OS(es) Affected: Windows

Infostealer.Limitail is a Trojan that steals personal information and computer data from the affected computer. Once executed, Infostealer.Limitail copies itself to the certain location and creates the certain folder. Infostealer.Limitail takes screen shots and saves them to the particular location on the compromised PC. Infostealer.Limitail creates the specific registry entry so that it can run automatically every time you start Windows. Infostealer.Limitail also logs keystrokes and title bars of open windows. Infostealer.Limitail sends the stolen information to the certain location in an email format.

Aliases

Suspicious file [Panda]W32/Agent.XRPA!tr [Fortinet]Win32.SuspectCrc [Ikarus]Artemis!6E81B660816D [McAfee-GW-Edition]TR/Kazy.158415.130 [AntiVir]Trojan.DownLoader8.62676 [DrWeb]UnclassifiedMalware [Comodo]Trojan.Win32.Agent.xrpa [Kaspersky]Infostealer.Limitail [Symantec]RDN/Generic.tfr!co [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\AdobeUpdate.exe File name: AdobeUpdate.exe
Size: 36.86 KB (36864 bytes)
MD5: 02e3455a225769363b39e2bd6b3b420d
Detection count: 3,267
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\AdobeUpdate.exe
Group: Malware file
Last Updated: March 9, 2023
C:\Users\<username>\AppData\Roaming\AdobeUpdate.exe File name: AdobeUpdate.exe
Size: 42.49 KB (42496 bytes)
MD5: a5208c8c1d9634ea4fa769eaeb03376a
Detection count: 1,646
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\AdobeUpdate.exe
Group: Malware file
Last Updated: September 22, 2023
C:\Users\<username>\AppData\Roaming\AdobeUpdate.exe File name: AdobeUpdate.exe
Size: 36.86 KB (36864 bytes)
MD5: 0d2ed322548148a7972dc463cd88e3d8
Detection count: 119
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\AdobeUpdate.exe
Group: Malware file
Last Updated: October 3, 2022
%APPDATA%\SOCXN\ltc.exe File name: ltc.exe
Size: 8.19 KB (8192 bytes)
MD5: 6e81b660816d58af45635b722521f775
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\SOCXN
Group: Malware file
Last Updated: December 1, 2013
%UserProfile%\Application Data\Microsoft\SysAudio.exe File name: %UserProfile%\Application Data\Microsoft\SysAudio.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Application Data\Microsoft\Credentials\screen[NUMBER].png File name: %UserProfile%\Application Data\Microsoft\Credentials\screen[NUMBER].png
Mime Type: unknown/png
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\AdobeUpdate.exeHKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Google Updater" = "%UserProfile%\Application Data\Microsoft\SysAudio.exe"
Loading...