Threat Database Trojans Trojan.Win32.Lethic.F

Trojan.Win32.Lethic.F

By Domesticus in Trojans

Trojan:Win32/Lethic.F is a Trojan that connects to a remote server, which may enable cybercriminals to obtain remote access and control of a corrupted PC. When run, Trojan.Win32.Lethic.F downloads malevolent files on the targeted PC. Trojan.Win32.Lethic.F makes modifications to the registry entries. Trojan.Win32.Lethic.F uses code injection to bypass the detection and removal of anti-virus software. While being executed, Trojan:Win32/Lethic.F may inject a code into running processes, such as 'explorer.exe'. Win32/Lethic aims at creating a connection to remote servers through various TCP ports.

File System Details

Trojan.Win32.Lethic.F may create the following file(s):
# File Name Detections
1. C:\Recycler\s-1-5-21-0243336031-4052116379-881863308-0851\vse432.exe
2. C:\Recycler\s-1-5-21-0243236031-425636379-881863308-0455\freegifthq.exe
3. C:\Recycler\s-1-5-21-0243556031-888888379-781863308-1413\syitm.exe
4. C:\Recycler\s-1-5-21-0243336031-4052116379-881863308-0851\vss132.exe

Registry Details

Trojan.Win32.Lethic.F may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Tnaww" = "C:\Recycler\s-1-5-21-0243556031-888888379-781863308-1413\syitm.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Taskman"= "C:\Recycler\s-1-5-21-0243236031-425636379-881863308-0455\freegifthq.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "12CFG914-K641-26SF-N32P" = "C:\Recycler\s-1-5-21-0243336031-4052116379-881863308-0851\vse432.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Taskman" = "C:\Recycler\s-1-5-21-0243556031-888888379-781863308-1413\syitm.exe"
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "explorer.exe,C:\Recycler\s-1-5-21-0243556031-888888379-781863308-1413\syitm.exe"

Trending

Most Viewed

Loading...