









 |
W32/Boltolog.AML Trojan
| Name |
W32/Boltolog.AML Trojan |
| Aliases |
Trojan:W32/Vundo.RJ, Trojan-Downloader.Win32.Boltolog.aml. |
| Updated on |
May 20, 2009 |
Virus Information - W32/Boltolog.AML Trojan:
W32/Boltolog.AML is a trojan. The trojan will infect Windows systems.
Upon execution, the trojan drops the following files in Windows System folder:
rqRKDUKb.dll
ssqNEWmJ.dll
ewnqqvry.dll
qwyvpb.dll
SYS32DLL.exe
creats a folder 796525 and drops 796525.dll
It also drops the following files:
ld08.exe in WINDOWS folder (variable strings).exe in Documents and Settings\Default User\Local Settings\Temporary Internet Files
setup(variable strings).exe in Documents and Settings\Default User\Local Settings\Temporary Internet Files
vuuOtUyD.exe in Documents and Settings\Default User\Local Settings\Temp
The trojan modifies registry at the following locations:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_USERS\S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-XXXX\Software\Microsoft\Windows\CurrentVersion\Run

|