TROJ_SMALL.UUF

 Analysis by: Sabrina Lei Sioting

 PLATFORM:

Windows 2000, XP, Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes


  TECHNICAL DETAILS

File Size:

12,599,920 bytes

File Type:

EXE

File Compression:

PECompact

Memory Resident:

No

Initial Samples Received Date:

10 May 2011

Installation

This Trojan drops the following copies of itself into the affected system:

  • %Program Files%\LMN.hta
  • %Program Files%\Common Files\session\conlme.exe

(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)

It creates the following folders:

  • %Program Files%\Common Files\session

(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)

Autostart Technique

This Trojan adds the following registry entries to enable its automatic execution at every system startup:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
safety = %Program Files%\Common Files\session\conlme.exe

Other System Modifications

This Trojan adds the following registry entries as part of its installation routine:

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
default_page_url = http://www.52cailing.com

It modifies the following registry entries:

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
Start Page = http://www.52cailing.com

(Note: The default value data of the said registry entry is {default home page}.)

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
Search Page = http://www.52cailing.com

(Note: The default value data of the said registry entry is {default home page}.)