Home Malware Programs Trojans TROJ_HYDRAQ.E

TROJ_HYDRAQ.E

Posted: April 7, 2010

TROJ_HYDRAQ.E is a malicious Trojan which is downloaded from remote sites or dropped by other malware. TROJ_HYDRAQ.E registers itself as a system service to ensure its automatic execution at every system startup. TROJ_HYDRAQ.E does this by creating registry keys/entries. TROJ_HYDRAQ.E poses a risk to system security and should be removed immediately once detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\Rasmon.dll to svchost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}ErrorControl = "0"HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0~MHzHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RaS{random}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RaS{random}\ParametersHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RaS{random}\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ups{random}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ups{random}\ParametersHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ups{random}\SecurityImagePath = "%SystemRoot%\System32\svchost.exe -k netsvcs"ObjectName "LocalSystem"Security = "{Binary Values}"ServiceDll = "%System%\rasmon.dll"Services\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RaS{random}Services\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ups{random}Start = "2"Type = "20"
Loading...