Home Malware Programs Trojans New Malware.cc

New Malware.cc

Posted: August 16, 2011

New Malware.cc is identified as a dangerous trojan that runs in the background and is able to change Internet Explorer cookies to connect the compromised computer to rogue websites. New Malware.cc redirects the affected web browser to malicious websites and tries to upload potentially infected files onto the PC system. New Malware.cc enables remote attackers gain access to the targeted machine. New Malware.cc can steal private details collected on the attacked computer system It is strongly advised to eliminate New Malware.cc immediately after detection to secure your PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%\jbpiclth.bat File name: %AppData%\jbpiclth.bat
File type: Batch file
Mime Type: unknown/bat
%AppData%\MouseDriver.bat File name: %AppData%\MouseDriver.bat
File type: Batch file
Mime Type: unknown/bat
%AppData%\0bdfar.exe File name: %AppData%\0bdfar.exe
File type: Executable File
Mime Type: unknown/exe
%AppData%\1x97n2jeb.exe File name: %AppData%\1x97n2jeb.exe
File type: Executable File
Mime Type: unknown/exe
%Temp%\arp.bat File name: %Temp%\arp.bat
File type: Batch file
Mime Type: unknown/bat

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\tgs90gv74rHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\[filename of the sample #1 without extension]\DEBUGHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\0bdfar\DEBUGHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\0bdfar
Loading...