Home Malware Programs Trojans Trojan.Loopas.C!inf

Trojan.Loopas.C!inf

Posted: July 5, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 64
First Seen: July 5, 2012
OS(es) Affected: Windows

Trojan.Loopas.C!inf is a Trojan and detection for files that are affected by the Trojan.Loopas family of PC threats. Trojan.Loopas.C!inf may spread as a CHM (help) file that dowmloads the malicious payload. Once executed, Trojan.Loopas.C!inf copies itself as the certain file. Trojan.Loopas.C!inf also drops potentially malicious files. Trojan.Loopas.C!inf then corrupts the particular file to launch the main file of the Trojan. Trojan.Loopas.C!inf then deletes numerous files. Trojan.Loopas.C!inf then modifies the Windows Registry.Trojan.Loopas.C!inf steals personal information from the infected computer, such as computer name, environment variables and IP address. The Trojan.Loopas.C!inf tries to access the domain called mail.winxps.com.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%CommonProgramFiles%\odbc.nls File name: %CommonProgramFiles%\odbc.nls
Mime Type: unknown/nls
Group: Malware file
%CommonProgramFiles%\odbc_lif.nls File name: %CommonProgramFiles%\odbc_lif.nls
Mime Type: unknown/nls
Group: Malware file
%CommonProgramFiles%\odbc_orp.nls File name: %CommonProgramFiles%\odbc_orp.nls
Mime Type: unknown/nls
Group: Malware file
%CommonProgramFiles%\odbc_dmc.nls File name: %CommonProgramFiles%\odbc_dmc.nls
Mime Type: unknown/nls
Group: Malware file
%CommonProgramFiles%\odbc_res.nls File name: %CommonProgramFiles%\odbc_res.nls
Mime Type: unknown/nls
Group: Malware file
%CommonProgramFiles%\odbc_rcs.nls File name: %CommonProgramFiles%\odbc_rcs.nls
Mime Type: unknown/nls
Group: Malware file
%CommonProgramFiles%\odbc_ger.nls File name: %CommonProgramFiles%\odbc_ger.nls
Mime Type: unknown/nls
Group: Malware file
%CommonProgramFiles%\odbc_rehto.nls File name: %CommonProgramFiles%\odbc_rehto.nls
Mime Type: unknown/nls
Group: Malware file
%CommonProgramFiles%\odbc_div.nls File name: %CommonProgramFiles%\odbc_div.nls
Mime Type: unknown/nls
Group: Malware file
%CommonProgramFiles%\odbc_txe.nls File name: %CommonProgramFiles%\odbc_txe.nls
Mime Type: unknown/nls
Group: Malware file
%CommonProgramFiles%\dumpodbc.exe File name: %CommonProgramFiles%\dumpodbc.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%System%\udpmon_old.dll File name: %System%\udpmon_old.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%System%\spoolss.dll (Trojan.Loopas!inf) File name: %System%\spoolss.dll (Trojan.Loopas!inf)
Mime Type: unknown/Loopas!inf)
Group: Malware file
%Temp%\s[FIVE RANDOM NUMBERS].dat File name: %Temp%\s[FIVE RANDOM NUMBERS].dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\"FailureActions" = "[BINARY DATA]"
Loading...