Virus Characteristics
This is a generic detection for Trojans. Trojan behavior can be found in various malware families like "downloader", "dropper", "backdoor", "password stealer", etc. They are standalone applications that might call other malware or infect your machine on executing.
They can act in various ways to steal your data, private information, or resources.
It enables backdoor functionalities by connecting to a remote site and performing actions as programmed by a remote attacker.
The following registry is used:
- HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Active Setup\Installed Components\{04D76A86-B759-FCF9-9BF3-BFB1C189EAC8}
"Stubpath" = "File Path\dllhost.exe"
The above mentioned registry activates on every reboot, and the Trojan variants register themselves.
It establish connection with the remote host 61.196.[removed] using the port 80.
The following mutex has been created:
It creates a mutex with the name "!VoqQ.I4"