Threat Database Trojans Trojan.VBS.Starter.eq

Trojan.VBS.Starter.eq

By JubileeX in Trojans

Trojan.VBS.Starter.eq is a Trojan that is able to exploit vulnerabilities in Internet Explorer in order to execute malicious code. Trojan.VBS.Starter.eq may enter a system via drive-by download or unsolicited e-mails. On entering a system, Trojan.VBS.Starter.eq will communicate with a remote server and download harmful files onto the compromised PC without a user's permission. Trojan.VBS.Starter.eq may also give remote attackers unauthorized access to the system.

File System Details

Trojan.VBS.Starter.eq may create the following file(s):
# File Name Detections
1. %Temp%\RarSFX0\Ser12.exe
2. %System%\WinH11.exe
3. %System%\WinH12.exe
4. %Temp%\RarSFX0\Ser11.exe
5. %Temp%\RarSFX0\ser.vbs

Registry Details

Trojan.VBS.Starter.eq may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINHELP12
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHe11\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINHE11
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINHELP12\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WinHelp12
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Setting
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINHE11\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHe11
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHelp12\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINHELP12
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WinHe11\Security
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINHE11
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINHELP12\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHelp12
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINHE11\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WinHe11
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WinHelp12\Security

Trending

Most Viewed

Loading...