Home Malware Programs Trojans PWSteal.Lageliz.A

PWSteal.Lageliz.A

Posted: August 1, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 21
First Seen: August 1, 2011
OS(es) Affected: Windows

PWSteal.Lageliz.A is a password stealing Windows Trojan that downloads lots of dynamic link library files (.dll) on the targeted computer. PWSteal.Lageliz.A can steal its victim's personal information. PWSteal.Lageliz.A can corrupt, delete processes, record keyboard inputs, create TCP (Transmission Control Protocol) ports, use personal IM chat and email accounts to distribute malicious files, or even change your web browser's settings. PWSteal.Lageliz.A can disguise itself from detection and removal by many security applications. PWSteal.Lageliz.A can drop other malware threats. PWSteal.Lageliz.A can also tamper with your Windows Security Center, making it unresponsive to PWSteal.Lageliz.A infection, because of disabled attributes to inform you of the risk. PWSteal.Lageliz.A could also block access to Registry Editor and Task Manager services, which are important for removal of PWSteal.Lageliz.A from the corrupted PC. PWSteal.Lageliz.A contains capability of keylogging. PWSteal.Lageliz.A could easily copy the victim's key strokes made in specific websites and, thus, can steal sensitive banking information from the affected computer user.

Aliases

Generic Backdoor [Panda]Generic26.CCZ [AVG]TR/Spy.Aslant.A [AntiVir]Backdoor.Win32.Papras.ekq [Kaspersky]Win32:Spyware-gen [Spy] [Avast]W32/Agent.IV.gen!Eldorado [F-Prot]a variant of Win32/Kryptik.VXH [NOD32]Artemis!5E4BC46B7D94 [McAfee]Generic Malware [Panda]Win32/Heri [AVG]Virus.Win32.Heri [Ikarus]Win-Trojan/Papras.44032.D [AhnLab-V3]BDS/Backdoor.Gen5 [AntiVir]UnclassifiedMalware [Comodo]Backdoor.Win32.Papras.epf [Kaspersky]
More aliases (75)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\logmtugc.dll File name: logmtugc.dll
Size: 59.9 KB (59904 bytes)
MD5: ef8c2a6d469d90ac263d90a92074a1de
Detection count: 93
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: August 1, 2011
%TEMP%\findasrv.dll File name: findasrv.dll
Size: 45.56 KB (45568 bytes)
MD5: 742b5669339ed6ecf52a5328b3d3c874
Detection count: 75
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: November 23, 2011
%TEMP%\cacll386.dll File name: cacll386.dll
Size: 44.03 KB (44032 bytes)
MD5: ffccde52bfbad88e43c56e425a913996
Detection count: 62
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: December 22, 2011
c:\CEZAR-F092D3AAC\windowsinstaller.dll File name: windowsinstaller.dll
Size: 403.45 KB (403456 bytes)
MD5: 9e89b13cb8748ebf039f33bb4d80ba1b
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: c:\CEZAR-F092D3AAC
Group: Malware file
Last Updated: August 10, 2011
%TEMP%\cmdalua.dll File name: cmdalua.dll
Size: 47.61 KB (47616 bytes)
MD5: 5e4bc46b7d946007ecfc77b472f00527
Detection count: 1
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: January 10, 2012
Loading...