Home Malware Programs Trojans Trojan.Win32.Regrun.bac

Trojan.Win32.Regrun.bac

Posted: May 13, 2010

Trojan.Win32.Regrun.bac is a malicious Trojan horse that may represent security risk for the compromised system or its network environment. Trojan.Win32.Regrun.bac uses backdoors to install contaminated files from the internet onto a compromised computer. Trojan.Win32.Regrun.bac may spread via drive-by downloads and does not require a user's permission to run on a computer. Trojan.Win32.Regrun.bac comes bundled with a malicious installation program. Remove Trojan.Win32.Regrun.bac as soon as it has been detected.

Aliases

Troj/VB-ELX (Sophos)
Win-Trojan/Regrun.143360.F (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Common Files\eolqusgr.exe
    2 %System%\mkwyikiu.exe
    3 %System%\Restore\12052010.kp_
    4 %System%\svj.exe
    5 %Windir%\Config\yuu.exe
    6 %Windir%\inf\vdv.exe
    7 %Windir%\qomssxcx.exe
    8 %Windir%\system\tiebez.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Default][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...