Home Malware Programs Trojans Trojan:Win32/Crastic.gen!A

Trojan:Win32/Crastic.gen!A

Posted: July 3, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 74
First Seen: July 3, 2013
Last Seen: November 7, 2019
OS(es) Affected: Windows

Trojan:Win32/Crastic.gen!A is a Trojan that steals personal information of a target computer user and transmits it to a remote attacker, such as user names, passwords and information about an infected computer. Trojan:Win32/Crastic.gen!A can also delete System Restore points making it more difficult to recover the affected computer to a pre-infected state. Trojan:Win32/Crastic.gen!A is installed and run on the compromised PC from a removable drive by another malware threat. Once instlled, Trojan:Win32/Crastic.gen!A downloads the potentially malicious files and makes registry modifications. Trojan:Win32/Crastic.gen!A uses the certain techniques to make analysis more difficult. Trojan:Win32/Crastic.gen!A runs only from a removable drive, detects reverse engineering software such as OllyDBG, WinDbg, Process Explorer and WireShark, and detects emulation environments, such as Virtualbox, Hyper-v, VMware. Trojan:Win32/Crastic.gen!A will stop running if it finds any of these reverse engineering or emulation environments on the targeted computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%windir%/csrss.dll File name: %windir%/csrss.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wcsrss "ImagePath" = "%SystemRoot%\system32\svchost.exe -k Wcsrss"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wcsrss\Parameters "ServiceDll" = "%SystemRoot%\csrss.dll"
Loading...