Home Malware Programs Trojans Chiznit

Chiznit

Posted: June 1, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 70
First Seen: June 1, 2012
OS(es) Affected: Windows

Chiznit is a Trojan, which is produced to copy malicious files into programs. Chiznit modifies the Windows Registry so that it can run itself automatically every time you start windows. Chiznit is controlled by remote attackers and can drop additional malware threats to the affected PC. Chiznit controls the computer work and saves values and other data to log files and registry keys.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load = "%WinDir%\AppPatch\.exe,"HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run = "%WinDir%\AppPatch\.exe," HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = "%WinDir%\AppPatch\.exe,"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = "%WinDir\AppPatch\([RANDOM CHARACTERS])\.exe\,"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System = "%WinDir%\AppPatch\.exe,"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System = "%WinDir\AppPatch\([RANDOM CHARACTERS])\.exe\,"HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load = "%WinDir\AppPatch\([RANDOM CHARACTERS])\.exe\,"HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run = "%WinDir\AppPatch\([RANDOM CHARACTERS])\.exe\,"HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\"44d228d9"
Loading...