Home Malware Programs Trojans Troj/Tracur-Gen

Troj/Tracur-Gen

Posted: January 25, 2010

Troj/Tracur-Gen is an evil Trojan that tends to disguise itself as a legitimate computer program. Troj/Tracur-Gen was intentionally created to intrude and disturb computer activities. Troj/Tracur-Gen is sometimes used together with other malware. Troj/Tracur-Gen can be installed without a user's full awareness and agreement. Troj/Tracur-Gen may cause a number of undesired security issues therefore it should be removed from a compromised system as soon as it is detected.

Aliases

Trojan Horse (Symantec)
Backdoor.Win32.Agent.amjd (Kaspersky Lab)
Troj/Fwdisab-B (Sophos)
Trojan-Dropper.Agent (Ikarus)
VBS/Xema (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\020000006175b901741C.manifest
    2 %AppData%\020000006175b901741O.manifest
    3 %AppData%\020000006175b901741P.manifest
    4 %AppData%\020000006175b901741S.manifest
    5 %AppData%\SystemProc\lsass.exe
    6 %ProgramFiles%\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
    7 %ProgramFiles%\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
    8 %ProgramFiles%\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
    9 %System%\iasads32.dll
    10 %System%\iasnap32.dll
    11 %System%\vH1nluLS3oSqu.vbs

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
Loading...