Additional Details
Trojan:W32/Dursg.D downloads additional files (possibly malware) from remote sites without the knowledge or authorization of the user.
ExecutionUpon executing, Trojan:W32/Dursg.D creates this directory:
It also creates these files under the new directory:
• %appdata%\SystemProc\lsass.exe - a copy of itself
• %appdata%\SystemProc\upd.exe
ActivityOnce installed, Dursg.D attempts to connect and download from the following websites:
• http://controllqz.com/[removed]?aid=hidden
• http://simfreebox.com/[removed]?sd=2010-05-15&aid=hidden
Trojan:W32:Dursg.D deletes itself after execution.
Registry ChangesThe following registry keys are created to set a launchpoint:
• HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
RTHDBPL = C:\Documents and Settings\user\Application Data\SystemProc\lsass.exe