- Add itself to registry for auto-execution on system reboot.
[PIC 1] Modified Internet Explorer's start page
[PIC 2] Internet Explorer's Tools
<Related Malicious Codes>
Adware.Xiaoliu
Adware.eMessageServer
<Related URL>
hxxp://d.(...).com/aztj.htm
hxxp://js.users.51.la/2366423.js
hxxp://web.51.(...)/go.asp?(...)http%3A//d.(...).com/aztj.htm
hxxp://d.(...).com/set.htm
hxxp://js.users.51.la/2366427.js
hxxp://web.51.(...)/go.asp?(...)http%3A//d.(...).com/set.htm
hxxp://d.(...).com/setup.exe
hxxp://web.51.(...)/go.asp?(...)http%3A//d.(...).com/set.htm
<File>
[Adware.Hao123.To.172544] creates files like below.
(System Folder)\oemlinkicon.ico
(System Folder)\shdoclcw.dll
(System Folder)\Storm2.exe
(System Folder)\Update.exe
[Adware.Hao123.To.172544] deletes, modifies below files.
(System Folder)\dllcache\shdoclc.dll
<Registry>
[Adware.Hao123.To.172544] creates registries like below.
HKLM\SOFTWARE\Classes\CLSID\{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}\DefaultIcon
Value: oemlinkicon.ico
HKLM\SOFTWARE\Classes\CLSID\{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}
Value: ?址大全
HKLM\SOFTWARE\Classes\CLSID\{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}
Name: InfoTip
Value: ?址大全
HKLM\SOFTWARE\Classes\CLSID\{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}\Instance\InitPropertyBag
Name: Command
Value: ?址大全
HKLM\SOFTWARE\Classes\CLSID\{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}\Instance\InitPropertyBag
Name: Param1
Value: hxxp://www.123456.cn/?start
HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping
Name: {6096E38F-5AC1-4391-8EC4-75DFA92FB32F}
Value: 0x00002001
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Name: WBOpen
Value: (System Folder)\Storm2.exe
- Before -
HKCU\Software\Microsoft\Internet Explorer\Main
Name: Start Page
Value: about:blank
HKLM\SOFTWARE\Classes\txtfile\shell\open\command
Value: %SystemRoot%\system32\NOTEPAD.EXE %1
- After -
HKCU\Software\Microsoft\Internet Explorer\Main
Name: Start Page
Value: hxxp://www.123456.cn/?u
HKLM\SOFTWARE\Classes\txtfile\shell\open\command
Value: d:\Browsers.exe %1
<Notation>
- "(System Folder)" could be different by OS and generally this is "C:WindowsSystem32".