TrojanDropper:Win32/Lisfel.A

By Domesticus in Trojans | 3 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

TrojanDropper:Win32/Lisfel.A Description

TrojanDropper:Win32/Lisfel.A is a Trojan that distributes other Lisfel components on the compromised machine. When installed on the targeted computer system, TrojanDropper:Win32/Lisfel.A makes system changes by adding malevolent files and registry entries. TrojanDropper:Win32/Lisfel.A modifies the specific registry entry so that it can load its downloaded component every time you boot up Windows. TrojanDropper:Win32/Lisfel.A may invade the compromises PC via security threats that exploit the vulnerability described in CVE-2012-4969. TrojanDropper:Win32/Lisfel.A contacts an external server. TrojanDropper:Win32/Lisfel.A starts a disguised Internet browser window to access the server ‘receo.konkuk.ac.kr’, most likely to divert traffic to this server.

Type: Trojans

How Can You Detect TrojanDropper:Win32/Lisfel.A?

TrojanDropper:Win32/Lisfel.A Technical Report

As new TrojanDropper:Win32/Lisfel.A details are reported by our customers and findings from our Threat Research Center, we will update this section.

Fake message for TrojanDropper:Win32/Lisfel.A:

The following fake error message(s) appears for TrojanDropper:Win32/Lisfel.A:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun = “Kris” = “wlupdate.exe”

TrojanDropper:Win32/Lisfel.A Removal Details

TrojanDropper:Win32/Lisfel.A has typically the following processes in memory:

  • user.dll
  • wlupdate.exe
  • lisfl.dll

TrojanDropper:Win32/Lisfel.A creates the following files in the system:

  • tmp

Important Article Disclaimer

ESG Support Center

This entry was last updated on 10/16/12 and posted on 10/16/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.