Home Malware Programs Trojans Trojan.Stookit

Trojan.Stookit

Posted: April 17, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 40
First Seen: April 17, 2013
Last Seen: June 16, 2022
OS(es) Affected: Windows

Trojan.Stookit is a Trojan that modifies and infects the master boot record (MBR) and may steal information from the infected computer. When executed, Trojan.Stookit creates the potentially malicious files. Trojan.Stookit then creates the registry subkey. Trojan.Stookit attempts to log keystrokes and titles of active windows. Trojan.Stookit saves the grabbed information in the specific file. Trojan.Stookit attempts to transmit the grabbed information to the particular locations.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%\[RANDOM NUMBER].dll File name: %Temp%\[RANDOM NUMBER].dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Temp%\rdp.exe File name: %Temp%\rdp.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Anti.sys File name: C:\Anti.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\drivers\[RANDOM NUMBER].sys File name: %System%\drivers\[RANDOM NUMBER].sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\keylog.dat File name: %System%\keylog.dat
Mime Type: unknown/dat
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Anti
Loading...