TROJ_BHO.YO

Threat Type:
Destructiveness:
Encrypted:
In the wild:
OVERVIEW
This Trojan arrives via SMS messages.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives via SMS messages that contain the following details:
erfs
Autostart Technique
This Trojan registers itself as a system service to ensure its automatic execution at every system startup by adding the following registry entries:
u
r = tr
It adds the following registry entries to enable its automatic execution at every system startup:
hklm
run = a.exe
Other System Modifications
This Trojan adds the following registry keys:
q
q = q
SOLUTION
Step 1
Restore this modified registry value
Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer"s registry.
DATA_GENERIC_KEY_SHELL_1Default
%1 %*
- DATA_GENERIC_KEY_SHELL
command /c del regedit.com
Step 2
Download and apply this security patch Refrain from using these products until the appropriate patches have been installed. Trend Micro advises users to download critical patches upon release by vendors.
Did this description help? Tell us how we did.