| Malware name | Trojan.Agent.247296 | | Type | Trojan | | Affected platform | Win32 | | Media-Type | application/executable | | MD5 checksum | D38815B9E2DF47994DC301AD5EB7E3C2 | | Static file | yes | | Filesize | 247,296 Bytes | Alias names (also known as) | | Webwasher Proactive | Virus.Win32.FileInfector.gen | | McAfee | PWS-Banker.dldr |
| | Protection | | Webwasher Proactive | Database Version: 70 |
| | Side effects | Registry modification | | Propagation | No own spreading routine |
|
Description:
Registry
It registers a browser helper object (BHO) by adding the following key:
– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{18CB1A7B-94CD-4582-8022-ADA16851E44B}]
• (Default)="LabelCommand module"
The following registry keys are added:
– [HKCR\CLSID\{18CB1A7B-94CD-4582-8022-ADA16851E44B}\InprocServer32]
• "(Default)"="
%malware execution directory%\
%executed file%"
• "ThreadingModel"="Apartment"
– [HKCR\LabelCommand.LabelCommand\CurVer]
• (Default)="LabelCommand.LabelCommand.1"
File details
Programming language:
The malware program was written in MS Visual C++.
Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer:
• UPX