Home Malware Programs Trojans Chuvazada

Chuvazada

Posted: March 28, 2006

Chuvazada is a trojan designed to collect computer information and transfer stolen data to a predetermined web server. The spyware gathers details of the file computer, current user account and PC name. It can hide itself by injecting malicious code into running legitimate processes. Chuvazada automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 policy.dll
    2 syspol.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerExtent1=[value]HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun(Default)=[pathtosyspol.exe]
Loading...