









 |
W32/Exchanger.F Trojan
| Name |
W32/Exchanger.F Trojan |
| Aliases |
Win32:Zlob-BVC, Trojan-Downloader.Win32.Exchanger.f, Trojan.Crypt.XPACK.Gen, Troj/Agent-GVE |
| Discovered on |
April 04, 2008 |
Virus Information - W32/Exchanger.F Trojan:
W32/Exchanger.F is a trojan. The trojan will infect Windows systems.
Upon execution, the trojan drops CbEvtSvc.exe in Windows System folder.
The trojan creates a service with the following characteristics:
Service name: CbEvtSvc Display name: CbEvtSvc Image Path: %SystemRoot%\System32\CbEvtSvc.exe -k netsvcs Startup Type: Automatic
The trojan registers itself to run as a service by creating subkey in the following registry entries;
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services 
|