Win32/Wigon [Threat Name] go to Threat

Win32/Wigon.PH [Threat Variant Name]

Category trojan
Size 38400 B
Detection created Dec 11, 2012
Signature database version 8576
Aliases Backdoor.Win32.Pushdo.qkk (Kaspersky)
Short description

Win32/Wigon.PH is a trojan which tries to download other malware from the Internet. The file is run-time compressed using UPX .

Installation

When executed, the trojan copies itself in some of the the following locations:

  • %allusers%\­lufjovenomer.exe
  • %userprofile%\­lufjovenomer.exe

In order to be executed on every system start, the trojan sets the following Registry entries:

  • [HKEY_LOCAL_MACHINE\­Software\­Microsoft\­Windows\­CurrentVersion\­Run]
    • "lufjovenomer.exe" = "%allusers%\­lufjovenomer.exe"
  • [HKEY_CURRENT_USER\­Software\­Microsoft\­Windows\­CurrentVersion\­Run]
    • "lufjovenomer.exe" = "%userprofile%\­lufjovenomer.exe"

The following Registry entries are set:

  • [HKEY_LOCAL_MACHINE\­Software\­Microsoft\­Windows\­CurrentVersion]
    • "AppManagement" = %variable1%
    • "lufjovenomerzap" = %variable2%
  • [HKEY_CURRENT_USER\­Software\­Microsoft\­Windows\­CurrentVersion]
    • "AppManagement" = %variable%
    • "lufjovenomerzap" = %variable2%

A variable numerical value is used instead of %variable1-2% .

Information stealing

The trojan collects the following information:

  • operating system version

The trojan attempts to send gathered information to a remote machine.

Other information

The trojan acquires data and commands from a remote computer or the Internet.


The trojan contains a list of (250) URLs. The trojan generates various URL addresses. The HTTP protocol is used.


It can execute the following operations:

  • download files from a remote computer and/or the Internet
  • run executable files
  • uninstall itself
  • update itself to a newer version

The trojan can create and run a new thread with its own program code within the following processes:

  • %systemroot%\­system32\­svchost.exe

Please enable Javascript to ensure correct displaying of this content and refresh this page.