Virus Characteristics
Trojan-FAGQ!BC9D53F19486 is installed by other malware and may be present as a file named "n.dll". The Trojan component is responsible for downloading other malicious components.
ZeroAccess Trojan moderates an infected user's Internet experience by modifying search results, and generating pay-per-click advertising revenue for the owner of the website.
Upon execution, the Trojan drops the following files and connects to the following site 209.208.79.128 through remote port 80.
- %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\@
- %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n
- %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\@
- %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n
Also the Trojan has communication with the following IP Addresses
- 208.91.207.10 through remote port 80
- 66.85.130.234 through remote port 53
The following registry keys have been created
- HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}
- HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}
The following registry values have been added
- HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32
ThreadingModel = "Both"
(Default) = "%UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n"
The following registry values have been modified
- HKEY_LOCAL_MACHINE\Software\Classes\ClsId\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32\
= ”\\.\globalroot\systemroot\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n."
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\
RefCount = 0x1
The following directories have been created
- %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}
- %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\L
- %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\U
- %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}
- %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\L
- %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\U
[ Note – %UserProfile% - C:\Documents and Settings\[User Name] %WinDir% - C:\WINDOWS]