Home Malware Programs Trojans Trojan.Win32.VB.oyl

Trojan.Win32.VB.oyl

Posted: October 23, 2009

Trojan.Win32.VB.oyl is a malicious trojan horse that is security risk to the corrupted computer system and/or its network environment. Trojan.Win32.VB.oyl
creates outbound traffic and downloads malicious files from the Internet.

Aliases

Trojan.Win32.Koblu.lv
Trojan.Win32.Delf.mob
Backdoor.Win32.RefpronTrojan.Win32.Delf.mnb (Kaspersky Lab)
Trojan-Downloader.Win32.Delf.ttv
(Kaspersky Lab)
Trojan.Win32.Koblu.lv (Kaspersky Lab)
Trojan.Win32.Delf.mob (Kaspersky Lab)
Backdoor.Win32.Refpron (Ikarus)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\dncyool64.sys
    2 %System%\dpcxool64.sys
    3 %System%\sopidkc.exe
    4 %System%\tpsaxyd.exe
    5 %Temp%\mpj99938.dll
    6 %Temp%\mta13187.dll
    7 %Temp%\x1c16960.dll
    8 %Windir%\Temp\mpj116670.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\WinRAR SFXHKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPIDKCHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPIDKC\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPIDKC\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BtwSrvHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BtwSrv\ParametersHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BtwSrv\SecurityHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sopidkcHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sopidkc\EnumHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sopidkc\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKCHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC\0000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPIDKC\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BtwSrvHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BtwSrv\ParametersHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BtwSrv\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sopidkcHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sopidkc\EnumHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sopidkc\Security
Loading...