Skip to main content

Trojan-Spy:W32/Goldun.CW

Classification

Category:

Malware

Type:

Trojan-spy

Aliases:

  • Trojan-Spy:W32/Goldun.CW

Summary

This type of trojan secretly installs spy programs and/or keylogger programs.

Removal

Technical Details

Trojan-Spy:W32/Goldun.CW silently downloads and installs a file on the infected system. The downloaded file in turn downloads and executes another file which is most likely malware.

Arrival

Goldun.CW is distributed as an FSG packed EXE file. It creates and opens the following Bitmap file to hide its original intent:

Note: This image is saved in the default Temporary folder as screen.bmp.

Execution

Goldun.CW drops the following UPX-compressed DLL file on Windows System folder:

  • %systemdir%\mscods.dll

Note: %systemdir% by default is C:\Windows\system32.The DLL will connect, download, and execute a file from the following URL:

  • http://everythingdiscounted.biz/store/images/extras/[...].jpg

The code containing the above URL is encrypted using a simple XOR routine.The executed file drops a file named vbrs.bat into the default Temporary folder. The BAT file deletes the EXE file and the BAT file itself, effectively removing all traces of the malware on the system.

Registry

The DLL file is installed as a Browser Helper Object (BHO) so that when ever an Internet Explorer session is started, the DLL will also execute. It does this by creating the following Registry keys:

  • [HKCR\CLSID\{45357971-2534-8760-3685-423479197575}]
  • [HKLM\SOFTWARE\Classes\CLSID\{45357971-2534-8760-3685-423479197575}]

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.