|
Threat Encyclopaedia | Print this pageSend |
|
Installation
When executed, the trojan copies itself in the %temp% folder using the following filename:
The following file is dropped in the same folder:upxdn.exe
Size of the file is approximately 7 kB. The library is loaded and injected in the following process:upxdn.dll
In order to be executed on every system start, the trojan sets the following Registry entry:explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"upxdn" = "%temp%\upxdn.exe"
Information stealing
The trojan collects information related to the on-line game Zhengtu. The trojan can send the information to a remote machine. The HTTP protocol is used.