Home Malware Programs Trojans Trojan.Stabuniq

Trojan.Stabuniq

Posted: December 19, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 12
First Seen: December 19, 2012
Last Seen: March 30, 2022
OS(es) Affected: Windows

Trojan.Stabuniq is a Trojan that steals personal information from the infected computer. Once executed, Trojan.Stabuniq may create potentially malicious files on the affected PC. Trojan.Stabuniq adds registry entries so that it can run automatically every time Windows starts. Trojan.Stabuniq sends the stolen information to a remote location.

Trojan.Stabuniq distribution by type chart
Trojan.Stabuniq distribution by type chart - source: Symantec

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



malware_dump.exe File name: malware_dump.exe
Size: 61.44 KB (61440 bytes)
MD5: 493d0816244d6b789ad4a4f43e9f8299
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 7, 2013
vbwwd.exe File name: vbwwd.exe
Size: 72.7 KB (72704 bytes)
MD5: d0bfa4f8d663aa33e65f230d3e29cb57
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 7, 2013
C:\Users\<username>\Downloads\stabuniq_F31B797831B36A4877AA0FD173A7A4A2 File name: stabuniq_F31B797831B36A4877AA0FD173A7A4A2
Size: 79.36 KB (79360 bytes)
MD5: f31b797831b36a4877aa0fd173a7a4a2
Detection count: 76
Path: C:\Users\<username>\Downloads\stabuniq_F31B797831B36A4877AA0FD173A7A4A2
Group: Malware file
Last Updated: March 30, 2022
488443fa2482abec2cb10101d2d7c803 File name: 488443fa2482abec2cb10101d2d7c803
Size: 58.88 KB (58880 bytes)
MD5: 488443fa2482abec2cb10101d2d7c803
Detection count: 75
Group: Malware file
Last Updated: January 7, 2013
%ProgramFiles%\[FOLDER NAME ONE]\[FOLDER NAME TWO]\issch.exe File name: %ProgramFiles%\[FOLDER NAME ONE]\[FOLDER NAME TWO]\issch.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\[FOLDER NAME ONE]\[FOLDER NAME TWO]\smagent.exe File name: %ProgramFiles%\[FOLDER NAME ONE]\[FOLDER NAME TWO]\smagent.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\[FOLDER NAME ONE]\[FOLDER NAME TWO]\jqs.exe File name: %ProgramFiles%\[FOLDER NAME ONE]\[FOLDER NAME TWO]\jqs.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\[FOLDER NAME ONE]\[FOLDER NAME TWO]\acroiehelper.exe File name: %ProgramFiles%\[FOLDER NAME ONE]\[FOLDER NAME TWO]\acroiehelper.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\[FOLDER NAME ONE]\[FOLDER NAME TWO]\groovemonitor.exe File name: %ProgramFiles%\[FOLDER NAME ONE]\[FOLDER NAME TWO]\groovemonitor.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Stability Software\"Uniq" = "[RANDOM GUID]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM GUID]" = "[FILE NAME]"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM GUID]" = "[FILE NAME]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM GUID]" = "[FILE NAME]"
Loading...