answersLogoWhite

0

How trojan.hider.i works?

User Avatar

Pranav2591

Lvl 1
17y ago
Updated: 8/16/2019

When Trojan.Hider.i is executed, it performs the following activities:

It creates the below file which is copy of itself

%system%\isass.exe

For autoexecution it create the below registry entry

"ImagePath" = "%System%\isass.exe "

HKLM\System\CurrentControlSet\Services\CSNetManagerXp

"UncheckedValue" = "1" HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt "HideFileExt"="1"

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced

The file isass.exe is registered as a new system driver service named "CSNetManagerXp", with a display name of "CSNetManagerXp" and a startup type of automatic, so that it is started automatically during system startup.

User Avatar

Wiki User

17y ago

What else can I help you with?