TROJ_SMALL.UUF
Windows 2000, XP, Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
TECHNICAL DETAILS
12,599,920 bytes
EXE
PECompact
No
10 May 2011
Installation
This Trojan drops the following copies of itself into the affected system:
- %Program Files%\LMN.hta
- %Program Files%\Common Files\session\conlme.exe
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)
It creates the following folders:
- %Program Files%\Common Files\session
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
safety = %Program Files%\Common Files\session\conlme.exe
Other System Modifications
This Trojan adds the following registry entries as part of its installation routine:
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
default_page_url = http://www.52cailing.com
It modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
Start Page = http://www.52cailing.com
(Note: The default value data of the said registry entry is {default home page}.)
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
Search Page = http://www.52cailing.com
(Note: The default value data of the said registry entry is {default home page}.)