Trojan-Downloader.Win32.Braidupdate.c

| No Comments | No TrackBacks

Trojan-Downloader.Win32.Braidupdate.c

Aliases
Trojan-Downloader.Win32.Braidupdate.c (Kaspersky Lab) is also known as: TrojanDownloader.Win32.Braidupdate.c (Kaspersky Lab), Trojan.Braid (Doctor Web),   TROJ_BRAIDUPDT.C (Trend Micro),   TR/Dldr.Braidupda.C (H+BEDV),   Win32:Trojano-363 (ALWIL),   Downloader.Braidupdate.C (Grisoft),   Worm.WinUpToDate (ClamAV),   Trj/Downloader.PO (Panda),   Win32/TrojanDownloader.Braidupdate.C (Eset)

This Trojan downloads another program via the Internet and launches it on the victim machine without the user's knowledge or consent. It is a Windows PE EXE file. It is 79360 bytes in size. It is written in C++.

Installation

In order to ensure that the Trojan is launched automatically each time the system is restarted, the Trojan registers its executable file in the system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RunWindowsUpdate" = "<path to executable Trojan file> "

Payload

Once launched, the Trojan creates the following system registry key:

[HKLM\Software\Microsoft\Windows\CurrentVersion\RunWindowsUpdate]
"Gid" = "026133246127060045718030656336"

It then sends the following request:

http://www.uptodate.browse*****.com/perl/uptodate.pl?action=any&gid=026133246127060045718030656336&clientversion=1.0.7_ST&county=&cls=&isof=00

On contact with the URL shown above a parameter is added which transmits the latest version of the Trojan program. If there is no new version of the Trojan program available, the server sends the following answer: "<OK>". If there is a more recent version available, the server sends a link to the file containing the new version. The Trojan downloads an updated version of itself and saves it to the temporary directory under the following name:

%Temp%\_ps_inst.exe

The file is then launched for execution.

Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

  1. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
  2. Delete the following system registrykeys:
    [HKLM\Software\Microsoft\Windows\CurrentVersion\RunWindowsUpdate]
    "Gid" = "026133246127060045718030656336"
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RunWindowsUpdate" = "<path to executable Trojan file> "
  3. Empty the temporary directory (%Temp%).

No TrackBacks

TrackBack URL: http://avsecure.com/mt/mt-tb.cgi/13

Leave a comment

About this Entry

This page contains a single entry by AV Secure published on December 30, 2008 11:15 AM.

Trojan-Downloader_Win32_Agent.nmi was the previous entry in this blog.

Trojan-Downloader.JS.Agent.sg is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.