Home Malware Programs Trojans Infostealer.Donx

Infostealer.Donx

Posted: January 15, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 68
First Seen: January 15, 2013
OS(es) Affected: Windows

Infostealer.Donx is a Trojan that steals information and may download potentially malicious files on to the affected computer. When Infostealer.Donx is executed, it copies itself to the specific location. Infostealer.Donx creates the registry entry so that it can run automatically every time you start Windows. Infostealer.Donx may perform numerous damaging actions on the corrupted PC such as steal system information and transfer it to a remote location, record keystrokes and transmit them to a remote location, and download and execute other files.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



vt-upload-tApsw File name: vt-upload-tApsw
Size: 1.01 MB (1011712 bytes)
MD5: 75bc4237f45a2cd645d4ff99eb10a347
Detection count: 71
Group: Malware file
Last Updated: January 17, 2013
vt-upload-zqfLc File name: vt-upload-zqfLc
Size: 1.02 MB (1028096 bytes)
MD5: e41edcb85c80402137487d6be7533a5c
Detection count: 67
Group: Malware file
Last Updated: January 17, 2013
%SystemDrive%\Documents and Settings\All Users\Common Files\donx.exe File name: %SystemDrive%\Documents and Settings\All Users\Common Files\donx.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"donx" = "%SystemDrive%\Documents and Settings\All Users\Common Files\donx.exe"
Loading...