Home Malware Programs Trojans Trojan.Win32.Zapchast.affv

Trojan.Win32.Zapchast.affv

Posted: April 4, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 14
First Seen: April 4, 2013
Last Seen: May 5, 2022
OS(es) Affected: Windows

Trojan.Win32.Zapchast.affv is a Trojan that is included in the targeted attacks being sent via a web address registered in Shanghai. The titles of the malevolent document distributing Trojan.Win32.Zapchast.affv either point to articles from Men's Health magazine, involve military issues, or have Cyrillic file names. If opened, the malevolent documents will display a text document that involves the information promised in the title, while Trojan.Win32.Zapchast.affv is installed on the corrupted PC. When the exploit is run, it creates and runs a file named 'wordupgrade.exe'. This executable file downloads a DLL file named 'usrsvpla.dll' into the system32 directory and changes the WmdmPmSN (Portable Media Serial Number Service) registry key to load the DLL into 'svchost.exe'. The malware infection, 'usrsvpla.dll', installed by these malevolent documents is a variation of Enfal/Lurid, found as Trojan.Win32.Zapchast.affv.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



wordupgrade.exe File name: wordupgrade.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
usrsvpla.dll File name: usrsvpla.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Loading...