Threat Database Trojans Trojan:Win32/Matsnu.D

Trojan:Win32/Matsnu.D

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 31
First Seen: May 15, 2013
Last Seen: January 25, 2020
OS(es) Affected: Windows

Trojan:Win32/Matsnu.D is a Trojan that makes modifications to the affected PC to make it more vulnerable for other malware threats, and contacts a remote host to retrieve commands that can have practically any aim. When installed and run, Trojan:Win32/Matsnu.D makes system changes by making modifications to the Windows Registry. Trojan:Win32/Matsnu.D creates copies of itself to the particular locations with a random file name. Trojan:Win32/Matsnu.D modifies the registry entries to assure that its copy loads automatically whenever you start Windows. Trojan:Win32/Matsnu.D disables registry editing tools and task manager by modifying the Windows Registry. Trojan:Win32/Matsnu.D deletes the original copy of itself that runs when the PC user reboots the PC by modifying the Windows Registry. Trojan:Win32/Matsnu.D uses code insertion in order to evade detection and removal, it embeds a code and creates a remote thread in the running processes of 'svchost.exe'.

File System Details

Trojan:Win32/Matsnu.D may create the following file(s):
# File Name Detections
1. [system folder]\6c135f46acc0e9de4b69.exe
2. %TEMP%\cdbukngmoz.pre

Registry Details

Trojan:Win32/Matsnu.D may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon "userinit" = "[system folder]\userinit.exe, [system folder]\6c135f46acc0e9de4b69.exe,"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager "PendingFileRenameOperations" = "c:\documents and settings\administrator\local settings\temp\cdbukngmoz.pre"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe "Debugger " = "p9kdmf.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = "1"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe "Debugger " = "p9kdmf.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = "1"

Trending

Most Viewed

Loading...