Home Malware Programs Trojans Trojan.Darkshell

Trojan.Darkshell

Posted: April 12, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 91
First Seen: March 21, 2012
OS(es) Affected: Windows

Trojan.Darkshell is a Trojan that may launch distributed denial of service (DDoS) attacks. Once installed, Trojan.Darkshell copies itself to the certain location. Trojan.Darkshell also drops a rootkit with the certain file name. The rootkit modifies the System Service Dispatch Table (SSDT) in order to cover Trojan.Darkshell. Trojan.Darkshell then creates the particular registry subkey to add itself as a system service. Trojan.Darkshell also creates several registry entries. Trojan.Darkshell connects to the certain domain to post a unique identifier of the corrupted PC system and downloads a list of website links. Trojan.Darkshell then launches a distributed denial-of-service attack on the website links given. Remove Trojan.Darkshell immediately after detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%System%\drivers\PCIDump.sys File name: %System%\drivers\PCIDump.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\fkrekk[RANDOM NUMBERS].exe File name: %System%\fkrekk[RANDOM NUMBERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fkrkk[RANDOM NUMBERS]\"ErrorControl" = "0x00000000"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fkrkk[RANDOM NUMBERS]\"ImagePath" = "%System%\fkrekk[RANDOM NUMBERS].exe"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fkrkk[RANDOM NUMBERS]\"DisplayName" = "FkreFoxkk[RANDOM NUMBERS]"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fkrkk[RANDOM NUMBERS]\"Description" = "FkreFoxkk Browser[RANDOM NUMBERS]"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fkrkk[RANDOM NUMBERS]\"ObjectName" = "LocalSystem"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fkrkk[RANDOM NUMBERS]\"Start" = "0x00000002"HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fkrk[RANDOM NUMBERS]HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fkrkk[RANDOM NUMBERS]\"Type"
Loading...