Home Malware Programs Trojans Infostealer.Sazoora

Infostealer.Sazoora

Posted: May 28, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 47
First Seen: May 28, 2013
Last Seen: July 26, 2023
OS(es) Affected: Windows

Infostealer.Sazoora is a Trojan that steals information from the corrupted PC. When executed, Infostealer.Sazoora copies itself as the potentially malicious file. Infostealer.Sazoora creates the registry entry so that it can load automatically every time Windows is started. Infostealer.Sazoora then creates more registry entries. Infostealer.Sazoora steals information by monitoring the certain online banking websites. Infostealer.Sazoora also monitors the web browsers Mozilla Firefox, Google Chrome and Internet Explorer in an effort to steal further information. Infostealer.Sazoora may create the log file used to store the stolen information. Infostealer.Sazoora then transmits the gathered data to the specific locations.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%\log32.txt File name: %Temp%\log32.txt
Mime Type: unknown/txt
Group: Malware file
%UserProfile%\Application Data\WinHost\svchost.exe File name: %UserProfile%\Application Data\WinHost\svchost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"WindowsHost" = "%UserProfile%\Application Data\WinHost\svchost.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\svchost\WinHost\"wu" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\svchost\WinHost\"installed" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\svchost\WinHost\"path" = "%UserProfile%\Application Data\WinHost\svchost.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\svchost\WinHost\"Packet" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\svchost\WinHost\"guid" = "[VARIABLE GUID]"
Loading...