Home Malware Programs Malware SecurityRisk.PasswordRevealer

SecurityRisk.PasswordRevealer

Posted: July 7, 2010

SecurityRisk.PasswordRevealer is a hacktool that could be used by attackers to break into the system. SecurityRisk.PasswordRevealer can change Windows Explorer settings to download other malicious files from external servers. SecurityRisk.PasswordRevealer also has the ability to monitor user activities to obtain valuable personal information. SecurityRisk.PasswordRevealer poses a dangerous threat to any computer or system and should be terminated on detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\explorer\cd.txt
    2 %System%\explorer\Decrypt.txt
    3 %System%\explorer\pic\Img%.jpeg
    4 %System%\explorer\winlogon.exe
    5 %Temp%\iepv.txt
    6 %Temp%\IXP000.TMP\HIDDEN~2.EXE
    7 %Temp%\IXP000.TMP\STEAML~1.EXE
    8 %Temp%\Java Update.exe
    9 %Temp%\mess.txt
    10 %Temp%\U&P.txt
    11 %Temp%\Windows Defender.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
Loading...