Home / malwarePDF  

Trojan-Dropper:W32/Peed.gen!A


First posted on 24 March 2010.
Source: SecurityHome

Aliases :

There are no other names known for Trojan-Dropper:W32/Peed.gen!A.

Explanation :

A trojan that contains one or more malicious programs, which it will secretly install and execute.

Additional DetailsThis is the generic detection for malicious files that create a file directory under the temporary folder %temp%\E_4 (or %temp%\E_N4) upon execution.

The newly created folder is used to store files dropped by the following malware:
€ %temp%\E_4\krnln.fnr € %temp%\E_4\dp1.fne
The dropped files may be loaded in other processes to perform malicious activities.

Notes
€ Some variants may drop an executable files with random name inside a new created folder %windir%\system32\[folder with random names]. € Some variants from this family are observed to have downloading capabilities.

About generic detections


Unlike signature or single-file detections, a Generic Detection does not identify a unique or individual malicious program. Instead, a Generic Detection looks for broadly applicable code or behavior characteristics that indicate a file as potentially malicious, so that a single Generic Detection can efficiently identify dozens, or even hundreds of malware.

Last update 24 March 2010

 

TOP