Home Malware Programs Trojans Danmec

Danmec

Posted: March 28, 2006

Danmec is a trojan, which collects information about the compromised PC and transfers it to predetermined remote hosts. The spyware is interested in running processes, installed software, present folders, details on the operating computer and network adapter. Danmec injects malicious code into legitimate computer processes in order to hide its presence and activity. The trojan automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 _uninsep.bat
    2 checkreg.exe
    3 iisload.dll
    4 ws386l.ini
    5 wsl*.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunRegistryStartupCheck

Related Posts

Loading...