Threat Database Trojans TROJ_RUGENT.A

TROJ_RUGENT.A

By JubileeX in Trojans

TROJ_RUGENT.A is a Trojan that is a component of a spam emails attack related to Tibet and the London Summer Olympics 2012. The deceptive email has a subject line 'Tibet is not at the Olympics because China is still occupying Tibet'. TROJ_RUGENT.A may be dropped by other malware threats from remote websites. The fake email encompasses the attachment of the compressed file, which involves a bogus .DOC file called 'China's Olympic Legacy.docx'. When run, TROJ_RUGENT.A connects to certain domains to transfer and obtain information. TROJ_RUGENT.A can gather the victim's personal information and data about the affected PC. TROJ_RUGENT.A modifies the Windows Registry so that it can load automatically whenever you boot up your PC.

File System Details

TROJ_RUGENT.A may create the following file(s):
# File Name Detections
1. {Malware Path}\ker.dll
2. %User Temp%\wuauclt.exe
3. %Program Files%\WindowsZip\temp\Update\window.exe
4. %Program Files%\WindowsZip\temp\0.txt

Registry Details

TROJ_RUGENT.A may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders Common Startup = %Program Files%\WindowsZip\temp\Update
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows load = %User Temp%\wuauclt.exe

Trending

Most Viewed

Loading...