Home Malware Programs Trojans Trojan.Tracur!gen2

Trojan.Tracur!gen2

Posted: April 20, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 747
First Seen: April 20, 2012
OS(es) Affected: Windows

Trojan.Tracur!gen2 is Trojan that uses all possible ways to remain on the infected computer when a system scan is performed. Trojan.Tracur!gen2 attempts to avoid removal by adding a copy of its main file into System folder and naming it by the actual dll. A usual PC scanner, which trusts names, would delete Trojan.Tracur!gen2 on the pretext that its name matches the common knowledge system dll. Trojan.Tracur!gen2 registers itself as a COM Object so as to gain further trust of a scanner. Rootkits are used to worsen extermination of Trojan.Tracur!gen2 by blocking and even damaging potential removal tools. Trojan.Tracur!gen2 can interrupt the affected PC user's online requests on the compromised web browser by changing search results on any search engine to spam website links created by attackers. Trojan.Tracur!gen2 will forcibly redirect victims to suspicious web pages. Uninstall Trojan.Tracur!gen2 immediately after detection.

Aliases

Suspicious file [Panda]Sefnit.AH!tr [Fortinet]Trojan.Tracur [Ikarus]Trojan/Win32.Tracur [AhnLab-V3]Generic.evx!bx [McAfee-GW-Edition]UnclassifiedMalware [Comodo]UDS:DangerousObject.Multi.Generic [Kaspersky]Trj/Agent.JHW [Panda]W32/Sefnit.AH!tr [Fortinet]Artemis!E8AA9F65CE9A [McAfee-GW-Edition]Trojan.Tracur!gen2 [Symantec]Sefnit.ah [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Catalina Marketing Corp\Catalina Marketing Corp\dpvdx.dll File name: dpvdx.dll
Size: 548.86 KB (548864 bytes)
MD5: e8aa9f65ce9a16a65f4436268d635da0
Detection count: 454
File type: Dynamic link library
Mime Type: unknown/dll
Path: %APPDATA%\Catalina Marketing Corp\Catalina Marketing Corp
Group: Malware file
Last Updated: April 21, 2014
%APPDATA%\Intel Corporation\Intel Corporation\wmgaaaizl.dll File name: wmgaaaizl.dll
Size: 558.59 KB (558592 bytes)
MD5: 2ad056b24e90973151f69afc8976eeab
Detection count: 293
File type: Dynamic link library
Mime Type: unknown/dll
Path: %APPDATA%\Intel Corporation\Intel Corporation
Group: Malware file
Last Updated: August 8, 2012
Loading...