Home Malware Programs Trojans TrojanDownloader:Win32/Tracur.Y

TrojanDownloader:Win32/Tracur.Y

Posted: August 25, 2011

TrojanDownloader:Win32/Tracur.Y is a malicious Trojan that spreads through system vulnerabilities. TrojanDownloader:Win32/Tracur.Y downloads and executes arbitrary files and malicious programs to affected computer systems. TrojanDownloader:Win32/Tracur.Y connects to a remote computer and slows down network and computer work. TrojanDownloader:Win32/Tracur.Y disguises itself and hides in the background to avoid being detected and removed by security programs. Delete TrojanDownloader:Win32/Tracur.Y as quickly as possible to safeguard your PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Documents and Settings\<username>\Start Menu\TrojanDownloader:Win32/Tracur.Y File name: C:\Documents and Settings\<username>\Start Menu\TrojanDownloader:Win32/Tracur.Y
Mime Type: unknown/Y

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DBB4430-2805-4FF2-AC7D-43985BC678B8}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DBB4430-2805-4FF2-AC7D-43985BC678B8}\InprocServer32]HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\[filename of the sample #1 without extension].MsShutt_93\ClsidHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Services Network = "%Windir%\system\Services.exe"HKEY_CURRENT_USER\Software\Alx\ConfigHKEY_LOCAL_MACHINE\SOFTWARE\Description\Microsoft\Rpc\UuidTemporaryData (Default) = "Alx2000"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\[filename of the sample #1 without extension].MsShutt_93
Loading...