Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

TROJAN.SASFIS.AFUF

 

 

 

Name:

Trojan.Sasfis.afuf

Added:

October 9, 2011

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Description:

 

When Trojan.Sasfis.afuf is executed, it performs the following activities:

After execution, it drops the following files:

%Windir%\dwking.exe
%Windir%\system32\dwking0.dll
%Windir%\system32\sosv3.exe
%Windir%\system32\sosie0.dll
%Windir%\system32\sosmn0.dll
%Windir%\system32\sosmn1.dll

It creates/modifies the following registry entries:

SOS_reg = "%Windir%\system32\sosv3.exe"
HKU\Software\Microsoft\Windows\CurrentVersion\Run

win32 = "%Windir%\system32\sosie0.dll"
HKLM\Software\Classes\TypeLib\
{59FE46FB-228A-453F-9C81-AA6D46B97058}\1.0\0

VckingDllModuleName = "%Windir%\system32\dwking0.dll"
HKLM\Software\Classes\CLSID\
{90359234-04B2-A8D9-4A5D-F34B82327F64}

InprocServer32 = "%Windir%\system32\dwking0.dll"
HKLM\Software\Classes\CLSID\
{90359234-04B2-4A5D-A8D9-F34B82327F64}

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Malware problems?
We can help.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Evaluate Thirtyseven4 Antivirus Now

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4