Home Malware Programs Trojans Lazar

Lazar

Posted: March 28, 2006

Lazar, also known as Lazarus, is a trojan, which silently downloads from the Internet and installs numerous malware and adware threats without asking for user permission. The threat also contacts a predetermined web server to retrieve specific instructions and update its own configuration. Lazar may also overwrite default Hosts file in order to block access to certain Internet resources or send the user to undesirable web sites. The trojan automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 indexindicator.exe
    2 memreload.exe
    3 recalculate.exe
    4 reload.exe
    5 suiteoffices.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRundieselHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunindexindicatorHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunmemreloadHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsuiteeload

Related Posts

Loading...