Home Malware Programs Trojans Trojan-Dropper.Win32.Decay.dst

Trojan-Dropper.Win32.Decay.dst

Posted: February 24, 2010

Trojan-Dropper.Win32.Decay.dst is a Trojan Downloader program which aims to drop malware onto infected computers. Trojan-Dropper.Win32.Decay.dst is mostly installed through a vulnerability exploit or other tricky methods. Trojan-Dropper.Win32.Decay.dst helps to download and install other undesired software onto a victim's PC. Trojan-Dropper.Win32.Decay.dst may download adware, spyware or other malware from multiple servers or sources on the Internet.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\5_odbn.exe
    2 %Temp%\teste1_p.exe
    3 %Temp%\teste2_p.exe
    4 %Temp%\teste3_p.exe
    5 %Temp%\teste4_p.exe
    6 %Windir%\amoumain.exe
    7 %Windir%\ctfmon.exe
    8 %Windir%\lsass.exe
    9 %Windir%\odbn.exe
    10 %Windir%\servicelayer.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]HKEY..\..\..\..{RegistryKeys}NotifyDownloadComplete = "yes"amoumain = "%Windir%\amoumain.exe"ctfmon = "%Windir%\ctfmon.exe"lsass = "%Windir%\lsass.exe"odbny = "%Windir%\odbn.exe"servicelayer = "%Windir%\servicelayer.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...