Skip to main content

Trojan-Downloader:W32/Exchanger

Classification

Category:

Malware

Type:

Trojan-downloader

Aliases:

  • Trojan-Downloader:W32/Exchanger
  • Trojan-Downloader.Win32.Exchanger

Summary

Trojan-Downloader:W32/Exchanger variants download additional malicious software onto the infected system.

Removal

Technical Details

Once the trojan is executed it copies itself into the "system32" folder and starts itself from there as a service.The trojan also creates Windows registry entries to ensure that it is started every time the computer is started.Once running, Exchanger variants will attempt to contact a remote server in order to relay information about the infected machine. The server will reply with a list of URLs that point to malicious files to be downloaded.

File System Changes

Creates these files:

  • %windir%\system32\CbEvtSvc.exe

Process Changes

Creates these processes:

  • %windir%\system32\CbEvtSvc.exe

Registry Modifications

Sets these values:

  • HKLM\System\CurrentControlSet\Services\CbEvtSvc Type = 00000010 Start = 00000002 ErrorControl = 00000001 ImagePath = %SystemRoot%\System32\CbEvtSvc.exe -k netsvcs DisplayName = CbEvtSvc ObjectName = LocalSystem Opt =
  • HKLM\System\CurrentControlSet\Services\CbEvtSvc\Security Security = \x01\x00\x14\x80\x90\[...]

Creates these keys:

  • HKLM\System\CurrentControlSet\Services\CbEvtSvc
  • HKLM\System\CurrentControlSet\Services\CbEvtSvc\Security

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.