For Home

Virus Profile: Trojan-FAGQ!BC9D53F19486

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home N/A | Corporate N/A
Date Discovered: 5/16/2012
Date Added: 5/16/2012
Origin: N/A
Length: Varies
Type: Trojan
Subtype: -
DAT Required: N/A
Removal Instructions
   
 
 
   

Description

This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include e-mail, malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

Aliases –

  • Fortinet - W32/ZAccess.DGC!tr.bdr
  • Kaspersky - Trojan.Win32.Agent.sclu
  • Microsoft - Trojan:Win32/Sirefef.P
  • NOD32 - Win32/Sirefef.EV

Indication of Infection

The symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

Methods of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc
   

Virus Characteristics

Trojan-FAGQ!BC9D53F19486 is installed by other malware and may be present as a file named "n.dll". The Trojan component is responsible for downloading other malicious components.

ZeroAccess Trojan moderates an infected user's Internet experience by modifying search results, and generating pay-per-click advertising revenue for the owner of the website.

Upon execution, the Trojan drops the following files and connects to the following site 209.208.79.128 through remote port 80.

  • %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\@
  • %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n
  • %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\@
  • %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n

Also the Trojan has communication with the following IP Addresses

  • 208.91.207.10 through remote port 80
  • 66.85.130.234 through remote port 53

The following registry keys have been created

  • HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}
  • HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}

The following registry values have been added

  • HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32
    ThreadingModel = "Both"
    (Default) = "%UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n"

The following registry values have been modified

  • HKEY_LOCAL_MACHINE\Software\Classes\ClsId\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32\
    = ”\\.\globalroot\systemroot\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n."
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\
    RefCount  = 0x1

The following directories have been created

  • %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}
  • %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\L
  • %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\U
  • %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}
  • %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\L
  • %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\U

[ Note – %UserProfile% - C:\Documents and Settings\[User Name] %WinDir% - C:\WINDOWS]

   

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).