Home Malware Programs Trojans Satiloler

Satiloler

Posted: March 28, 2006

Satiloler is a trojan designed to steal user sensitive information.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 bluetooth.dll
    2 ctfmon.exe
    3 desktops.ini
    4 lsass.exe
    5 sfc_os.dll
    6 userinit.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunctfmon.exeHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunuserinitHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonSFCDisable=FFFFFF9DHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonSFCScan=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonuserinit

Related Posts

Loading...