Threat Database Worms W32.StuxnetQKY.Trojan

W32.StuxnetQKY.Trojan

By LoneStar in Worms

The W32.StuxnetQKY.Trojan is a component of the infamous Stuxnet worm. This malware infection contains several components and is considered extremely dangerous. According to ESG security researchers, the W32.StuxnetQKY.Trojan and the Stuxnet worm are a severe threat to your computer system's security. The main functionality of the W32.StuxnetQKY.Trojan is to monitor the activities between a DLL file and an application in order to steal information or use this data to further the Stuxnet infection on the victim's computer system. The main symptom of a W32.StuxnetQKY.Trojan infection is the presence of the s7otbxdx.dll file on your hard drive. The W32.StuxnetQKY.Trojan enters the infected computer system in this innocuous DLL file. This discriminates a wrapper for a legitimate component of the Siemens automation system Simatic S7 package. The W32.StuxnetQKY.Trojan monitors this legitimate DLL file, using the data W32.StuxnetQKY.Trojan gathers to steal important information.

The W32.StuxnetQKY.Trojan and the Stuxnet Worm

The Stuxnet worm received lots of media attention after a highly-publicized attack on high-profile targets. The Stuxnet family has many malware components that usually infect a computer system through a removable drive. It will usually take advantage of a Microsoft Vulnerability known as MS10-046. The Stuxnet infection has several components:

  1. The first component of a Stuxnet infection is the malware's dropper. This is an infection that drops and installs other two components of the Stuxnet infection on the victim's computer system. The Stuxnet worm mainly targets industrial equipment using particular software by Siemens.
  2. The second component of a Stuxnet infection is the W32.StuxnetQKY.Trojan, which loads the worm component as well as monitors the above-mentioned communications.
  3. Finally, the Stuxnet worm itself, which spreads from one computer to the next by detecting all drives connected to the infected computer system and creating copies of itself.

Since the original run of Stuxnet family infections, criminals have gained access to components of this dangerous family of malware. Using them, they have been able to craft Trojans such as the W32.StuxnetQKY.Trojan that allow them to infect home computer systems. These infections tend to spread through Facebook scams and dangerous file attachments contained in spam email messages. Since the W32.StuxnetQKY.Trojan is a relatively recent malware infection, it is essential to ensure that your security software is fully updated. Following basic online safety guidelines should also protect you from this dangerous invader.

URLs

W32.StuxnetQKY.Trojan may call the following URLs:

simpleconverters.com

Trending

Most Viewed

Loading...