Home Malware Programs Trojans Trojan.Mowhorc

Trojan.Mowhorc

Posted: December 20, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 36
First Seen: December 20, 2012
OS(es) Affected: Windows

Trojan.Mowhorc is a Trojan that affects .doc and .docx files on the infected computer. Once executed, Trojan.Mowhorc creates potentially malicious files. Trojan.Mowhorc adds registry entries so that it can run automatically every time you start Windows. Trojan.Mowhorc may search for .doc and .docx files, encrypt them and add a copy of itself. After this, Trojan.Mowhorc may change the filename extension from .doc or .docx to an .exe file extension.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



42b9d7e0d0b47890f879c41f8a14d0e1 File name: 42b9d7e0d0b47890f879c41f8a14d0e1
Size: 158.29 KB (158296 bytes)
MD5: 42b9d7e0d0b47890f879c41f8a14d0e1
Detection count: 7
Group: Malware file
Last Updated: January 7, 2013
%WinDir%\Temp\_$Cf\[TROJAN].docx File name: %WinDir%\Temp\_$Cf\[TROJAN].docx
Mime Type: unknown/docx
Group: Malware file
%WinDir%\Temp\_$Cf\osk.exe File name: %WinDir%\Temp\_$Cf\osk.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%System%\Com\ctfmoon.exe File name: %System%\Com\ctfmoon.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%System%\WINWORD.exe File name: %System%\WINWORD.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AUTOWORD" = "%System%\WINWORD.EXE"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "ctfmoon.exe" = "%System%\Com\ctfmoon.exe"
Loading...