Home Malware Programs Trojans TrojanDropper:Win32/Lisfel.A

TrojanDropper:Win32/Lisfel.A

Posted: October 16, 2012

Threat Metric

Ranking: 13,278
Threat Level: 9/10
Infected PCs: 326
First Seen: October 16, 2012
Last Seen: September 23, 2023
OS(es) Affected: Windows

TrojanDropper:Win32/Lisfel.A is a Trojan that downloads other Lisfel components on the infected computer system. When installed on the compromised PC, TrojanDropper:Win32/Lisfel.A makes system changes by dropping potentially malicious files and adding registry entries. TrojanDropper:Win32/Lisfel.A modifies the certain registry entry so that it can run its downloaded component every time you start Windows. TrojanDropper:Win32/Lisfel.A may come in the affected computer via malware infections that exploit the vulnerability described in CVE-2012-4969. TrojanDropper:Win32/Lisfel.A connects to a remote server. TrojanDropper:Win32/Lisfel.A starts a hidden web browser window to access the server 'receo.konkuk.ac.kr', most probably to direct traffic to this server.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



lisfl.dll File name: lisfl.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
wlupdate.exe File name: wlupdate.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
user.dll File name: user.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run = "Kris" = "\wlupdate.exe"
Loading...