Home Malware Programs Trojans Win32/Claretore

Win32/Claretore

Posted: April 12, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 19
First Seen: April 12, 2012
OS(es) Affected: Windows

Win32/Claretore is a Trojan that adds a malicious code into Windows processes to block web browser communication. Win32/Claretore may control the affected PC user's activity and transmit stolen information to a remote location. Win32/Claretore could also redirect the hijacked web browser to a malicious website link. Once executed, Win32/Claretore drops a copy of itself with 'hidden' and 'system' file attributes. Win32/Claretore modifies the Windows registry so that it can run each time you start Windows. Win32/Claretore has to be removed with a reputable anti-malware program.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Update Server" = "C:\Documents and Settings\Administrator\ec3fd7c0-0.exe"HKEY_LOCAL_MACHINE\\Machine\System\CurrentControlSet\Control\Session Manager "PendingFileRenameOperations" = "%Temp%\.tmp"

Additional Information

The following URL's were detected:
zationtothe.online
Loading...