Obvod (Microsoft), TrojanClicker (Eset)

 Piattaforma:

Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

 Valutazione del rischio complessivo:
 Potenziale dannoso: :
 Potenziale di distribuzione: :
 Reported Infection:
 Informazioni esposizione: :
Basso
Medio
Alto
Critico

  • Tipo di minaccia informatica:
    Trojan

  • Distruttivo?:
    No

  • Crittografato?:
     

  • In the wild::

  Panoramica e descrizione

Canale infezione: Descargado de Internet, Eliminado por otro tipo de malware


  Dettagli tecnici

Residente in memoria:
Carica distruttiva: Pay-per click fraud

Instalación

Infiltra y ejecuta los archivos siguientes:

  • %Windows%\Tasks\At1.job
  • %Windows%\Tasks\At2.job
  • %Windows%\Tasks\At3.job
  • %Windows%\Tasks\At4.job
  • %Windows%\Tasks\At5.job
  • %Windows%\Tasks\At6.job
  • %Windows%\Tasks\At7.job
  • %Windows%\Tasks\At8.job
  • %Windows%\Tasks\At9.job
  • %Windows%\Tasks\At10.job
  • %Windows%\Tasks\At11.job
  • %Windows%\Tasks\At12.job
  • %Windows%\Tasks\At13.job
  • %Windows%\Tasks\At14.job
  • %Windows%\Tasks\At15.job
  • %Windows%\Tasks\At16.job
  • %Windows%\Tasks\At17.job
  • %Windows%\Tasks\At18.job
  • %Windows%\Tasks\At19.job
  • %Windows%\Tasks\At20.job
  • %Windows%\Tasks\At21.job
  • %Windows%\Tasks\At22.job
  • %Windows%\Tasks\At23.job
  • %Windows%\Tasks\At24.job
  • %Windows%\Tasks\At25.job
  • %Windows%\Tasks\At26.job
  • %Windows%\Tasks\At27.job
  • %Windows%\Tasks\At28.job
  • %Windows%\Tasks\At29.job
  • %Windows%\Tasks\At30.job
  • %Windows%\Tasks\At31.job
  • %Windows%\Tasks\At32.job
  • %Windows%\Tasks\At33.job
  • %Windows%\Tasks\At34.job
  • %Windows%\Tasks\At35.job
  • %Windows%\Tasks\At36.job
  • %Windows%\Tasks\At37.job
  • %Windows%\Tasks\At38.job
  • %Windows%\Tasks\At39.job
  • %Windows%\Tasks\At40.job
  • %Windows%\Tasks\At41.job
  • %Windows%\Tasks\At42.job
  • %Windows%\Tasks\At43.job
  • %Windows%\Tasks\At44.job
  • %Windows%\Tasks\At45.job
  • %Windows%\Tasks\At46.job
  • %Windows%\Tasks\At47.job
  • %Windows%\Tasks\At48.job
  • %All Users Profile%\Application Data\5q2B8R.dat
  • %All Users Profile%\Application Data\{random file name}.exe.b
  • %All Users Profile%\Application Data\{random file name}.exe_.b

(Nota: %Windows% es la carpeta de Windows, que suele estar en C:\Windows o C:\WINNT).

)

Crea las siguientes copias de sí mismo en el sistema afectado:

  • %All Users Profile%\Application Data\{random file name}.exe

Otras modificaciones del sistema

Agrega las siguientes entradas de registro:

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
DisableScriptDebuggerIE = "yes"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
Error Dlg Displayed On Every Error = "no"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
NoProtectedModeBanner = "1"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\InternetSettings
WarnOnZoneCrossing = "0"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\InternetSettings\
Zones\3
2500 = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Direct3d
LA = "400"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Schedule
AtTaskMaxHours = "72"