Home Malware Programs Trojans Virus.Win32.HideProc.E

Virus.Win32.HideProc.E

Posted: July 30, 2010

Virus.Win32.HideProc.E (aka Win-Trojan/Click.2190848) is a malicious Trojan that runs in the background and has threat characteristics of a ZBot banking Trojan. Win-Trojan/Click.2190848 disables the firewall and attempts to steal sensitive financial data like credit card numbers, and online banking login details. Virus.Win32.HideProc.E creates a startup registry entries that load at boot of Windows. Win-Trojan/Click.2190848 is a malicious trojan horse that may represent a severe security risk for the compromised system and/or its network environment and should be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\drivers\hideproc.sys
    2 %System%\~DF1.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.uab\Excel2EXE7.0]HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HIDEPROC\0000\Control][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HIDEPROC\0000][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HIDEPROC][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hideproc\Enum][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hideproc\Security][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hideproc][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HIDEPROC\0000\Control][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HIDEPROC\0000][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HIDEPROC][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hideproc\Enum][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hideproc\Security][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hideproc]
Loading...