Threat Database Trojans Trojan.Tsyrval

Trojan.Tsyrval

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 25
First Seen: April 4, 2014
Last Seen: February 18, 2022
OS(es) Affected: Windows

Trojan.Tsyrval is a Trojan that transmits system information to distant locations. Trojan.Tsyrval may be distributed by a specially crafted document which exploits a vulnerability. Upon execution, Trojan.Tsyrval creates the potentially infected files. Trojan.Tsyrval creates the registry entry. Trojan.Tsyrval makes modifications to the registry entry. Trojan.Tsyrval transmits system information to the particular web addresses.

File System Details

Trojan.Tsyrval may create the following file(s):
# File Name Detections
1. %Temp%\[SIX RANDOM DIGITS]
2. %AllUsersProfile%\Application Data\Intel\Data\glp.uin
3. %AllUsersProfile%\Application Data\Intel\Data\Dtl.dat
4. %AllUsersProfile%\Application Data\Intel\buuu.dat
5. %AllUsersProfile%\Application Data\Intel\ResN32.dll
6. %AllUsersProfile%\Application Data\Intel\ResN32.dat
7. %AllUsersProfile%\Application Data\Intel\~1
8. %AllUsersProfile%\Application Data\Intel\rundll32.exe
9. %AllUsersProfile%\Application Data\Intel\~y.dll
10. %AllUsersProfile%\Documents\My Document\Dtl.dat
11. %AllUsersProfile%\Documents\My Document\glp.uin
12. %AllUsersProfile%\Documents\My Document\update\donhi.dat
13. %AllUsersProfile%\Documents\My Document\update\stage.dat
14. %AllUsersProfile%\Documents\My Document\update\sleptr.dat

Registry Details

Trojan.Tsyrval may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\"LoadAppInit_DLLs" = 0x00000001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\"AppInit_DLLs" = "%AllUsersProfile%\APPLIC~1\Intel\ResN32.dll"

URLs

Trojan.Tsyrval may call the following URLs:

Tsrvall.microsoft-centre.com
Tsrvall01.norton-update.com

Trending

Most Viewed

Loading...