Home Malware Programs Trojans Satiloler.e

Satiloler.e

Posted: March 28, 2006

Satiloler.e is a trojan designed to steal user sensitive information.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 b.reg
    2 bkup.reg
    3 ctfmon.exe
    4 divx.ini
    5 init.dll
    6 ip.sys
    7 lsass.exe
    8 sfc.dll
    9 sfc_os.dll
    10 tml_[X].exe
    11 userinit.exe
    12 xvid.dll
    13 xvid.ini

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunsystemHKEY_CURRENT_USERSoftwareMicrosoftxHKEY_CURRENT_USERSoftwareverHKEY_CURRENT_USERSoftwarevsHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWindowsAppInit_DLLs=%System%init.dllHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonSFCDisable=FFFFFF9DHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonSFCScan=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonsystem
Loading...