Virus Characteristics
Trojan-FAGQ!4CFF0EC30633 is a ZeroAccess Trojan, usually installed on a system by a malicious executable. Once this dropper is executed, it will install the rootkit and performs further malicious activity.
ZeroAccess Trojan moderates an infected user's Internet experience by modifying search results, and generating pay-per-click advertising revenue for the owner of the website.
Upon execution, the Trojan drops the following files and connects to the following site 209.208.79.128 through remote port 80.
- %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\@
- %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n
- %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\@
- %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n
Also the Trojan has communication with the following IP Addresses
- 208.91.207.10 through remote port 80
- 66.85.130.234 through remote port 53
The following registry keys have been created
- HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}
- HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}
The following registry values have been added
- HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32
ThreadingModel = "Both"
(Default) = "%UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n"
The following registry values have been modified
- HKEY_LOCAL_MACHINE\Software\Classes\ClsId\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32\
= ”\\.\globalroot\systemroot\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\n."
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\
RefCount = 0x1
The following directories have been created
- %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}
- %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\L
- %UserProfile%\Local Settings\Application Data\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\U
- %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}
- %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\L
- %WinDir%\Installer\{6576a1a8-5f9f-db0e-2056-8660563a58ee}\U
[ Note – %UserProfile% - C:\Documents and Settings\[User Name]%WinDir% - C:\WINDOWS]