Home Malware Programs Trojans Generic Downloader.x!bur

Generic Downloader.x!bur

Posted: December 8, 2009

Generic Downloader.x!bur is a Trojan downloader that stealthily enters the computer and executes a malicious file by exploiting software and security vulnerabilities. Generic Downloader.x!bur can also use emails, IRC and file-sharing networks to enter the system. Generic Downloader.x!bur can also download other spyware including a spyware keylogger which records keystrokes and captures the user's personal activity. Generic Downloader.x!bur should not be given any leeway to wreak havoc and must be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WinDir%\system32\flashcpx.dll
    2 %WinDir%\system32\mydpla.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{610D17B5-D7A7-44CB-83A7-ED2D39266CA2}\InprocServer32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{610D17B5-D7A7-44CB-83A7-ED2D39266CA2}\ProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{610D17B5-D7A7-44CB-83A7-ED2D39266CA2}\ProgrammableHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Explorer\Browser Helper Objects\{610D17B5-D7A7-44CB-83A7-ED2D39266CA2}83A7-ED2D39266CA2}
Loading...