Home Malware Programs Trojans KillSec

KillSec

Posted: March 28, 2006

KillSec is a trojan that attempts to steal login names, passwords, account details and other confidential information that the victim enters on certain German banking web sites. Gathered data is transferred to a predefined remote host. The spyware can run a hidden FTP server or a proxy. It may also download and run malicious files and block access to popular security-related web resources. KillSec runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 smss.exe
    2 winlogon.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTib1dll6.CBrowserHelperHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMicrosoftWindowsLogonProcessHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMicrosoftWindowsSessionManagerSubsystemHKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlInitRegKey
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}14A5F3E7-B235-4D98-9264-5C67D2657BC48C691F25-C565-4FB7-8BCC-E85169BD7C471E6CE4CD-161B-4847-B8BF-E2EF72299D69
Loading...