Home Malware Programs Trojans TROJ_FRAUDPAC.QL

TROJ_FRAUDPAC.QL

Posted: May 3, 2010

TROJ_FRAUDPAC.QL is a malicious Trojan which may be dropped by other malware. TROJ_FRAUDPAC.QL may arrive bundled with malware packages or as a malware component. TROJ_FRAUDPAC.QL drops copies of itself and is injected into processes running in memory. It adds keys as part of its installation routine. TROJ_FRAUDPAC.QL then registers itself as a system service to ensure its automatic execution at every system startup. It does this by creating registry keys/entries. TROJ_FRAUDPAC.QL can also connect to corrupt websites to download more malware on the system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\imagehlpj.exe
    2 SVCHOST.EXE

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}DisplayName = "Shell Hardware Detection ShellHWDetectionVMTools" ObjectName = "LocalSystem"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetectionVMToolsType = "110" Start = "2" ErrorControl = "0" ImagePath = "%System%\imagehlpj.exe srv"
Loading...