Win32:Downloader-FVM [Trj]

Win32:Downloader-FVM [Trj] also known as Trojan/Win32.Agent, TROJ_GEN.RC1C1HK.

Malware Analysis of Win32:Downloader-FVM [Trj]

Created files:

%SysDir%\ecologyplugin\fileupload\uninstall.bat
%SysDir%\ecologyplugin\fileupload\WeaverOcx.ocx
%SysDir%\krql.dll
%SysDir%\nuxe.dll
%SysDir%\system.exe

Autostart registry keys:

HKLM\Software\Classes\CLSID\{CBD79B8A-7975-4DD7-AF00-7E5ED70F7485}\InprocServer32\: “%SysDir%\ecologyplugin\fileupload\WeaverOcx.ocx”
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\system: “%SysDir%\system.exe”

Detected by UnHackMe:

KRQL.DLL
Default location: %SYSDIR%\KRQL.DLL

Leave a Reply