Home Malware Programs Trojans Satiloler.d

Satiloler.d

Posted: March 28, 2006

Satiloler.d is a trojan designed to steal user sensitive information.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cmd.txt
    2 ctfmon.exe
    3 divx5.dll
    4 h323.txt
    5 hst.txt
    6 lsass.exe
    7 sfc.dll
    8 sfc_os.dll
    9 userinit.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunctfmon.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunuserinitHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonSFCDisable=FFFFFF9DHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonSFCScan=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonSystemHKEY_LOCAL_MACHINESOFTWAREMicrosoftdHKEY_LOCAL_MACHINESOFTWAREMicrosoftgoldHKEY_LOCAL_MACHINESOFTWAREvrHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%System%userinit.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%Windir%Systemctfmon.exe
Loading...