Details:
Installation
This Trojan drops any of the following copy(ies) of itself:
- %System%\infocard.exe
- %System%\msmsgs.exe
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Autostart Techniques
This Trojan creates the following registry entry(ies) to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Framework module library = "%System%\infocard.exe"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Microsoft Msn Messenger = "%System%\msmsgs.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
Framework Module library = "%System%\infocard.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
Microsoft Msn Messenger = "%System%\msmsgs.exe"
Note that entries created depend on the name of the dropped copy.
Other System Modifications
This Trojan modifies the following registry key(s)/entry(ies) as part of its installation routine:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Ole
EnableDCOM = "N"
(Note: The default value data for the said registry entry is Y.)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Control\Lsa
restrictanonymous = "1"
(Note: The default value data for the said registry entry is 0.)
Internet Explorer Home Page and Search Page Modification
This Trojan modifies the Internet Explorer home page to point to the following Web site:
- http://www.{BLOCKED}ticles.net
Analysis By: Kathleen Mae Notario
Revision History: