Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:TR/Spy.BHO.aaa
Date discovered:22/04/2010
Type:Trojan
In the wild:Yes
Reported Infections:Low to medium
Distribution Potential:Low
Damage Potential:Low
Static file:Yes
File size:159.541 Bytes
MD5 checksum:d7bf064966ccbfc0b7954ccc007c7d97
IVDF version:7.10.06.171 - Thursday, April 22, 2010

 General Aliases:
   •  Sophos: Mal/EncPk-OD
   •  Bitdefender: Trojan.Generic.3856786
   •  Panda: W32/Lineage.LLI
   •  Eset: Win32/PSW.OnLineGames.QIE


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003


Side effects:
   • Drops malicious files
   • Registry modification

 Files It copies itself to the following location:
   • %SYSDIR%\anhdo.exe



It deletes the initially executed copy of itself.



The following files are created:

%SYSDIR%\ansb20.dll Further investigation pointed out that this file is malware, too. Detected as: TR/Spy.BHO.aaa.2

%SYSDIR%\ansb10.dll Further investigation pointed out that this file is malware, too. Detected as: TR/Spy.BHO.aaa.1




It tries to execute the following file:

– Filename:
   • %SYSDIR%\regsvr32.exe /s %SYSDIR%\ansb20.dll

 Registry The following registry key is added in order to run the process after reboot:

– [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "anhdo"="%SYSDIR%\anhdo.exe"



The following registry keys are added:

– [HKLM\SOFTWARE\Classes\CLSID\{C8414FA0-BA90-4600-B7EA-0CEFAF5A0636}\
   InprocServer32]
   • "@"="%SYSDIR%\ansb20.dll"
   • "ThreadingModel"="Apartment"

– [HKLM\SOFTWARE\Classes\CLSID\
   {C8414FA0-BA90-4600-B7EA-0CEFAF5A0636}]
   • "@"="IEHlprObj Class"

– [HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj]
   • "@"="IEHlprObj Class"

– [HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID]
   • "@"="{C8414FA0-BA90-4600-B7EA-0CEFAF5A0636}"

– [HKLM\SOFTWARE\Classes\CLSID\{C8414FA0-BA90-4600-B7EA-0CEFAF5A0636}\
   VersionIndependentProgID]
   • "@"="IEHlprObj.IEHlprObj"

– [HKLM\SOFTWARE\Classes\CLSID\{C8414FA0-BA90-4600-B7EA-0CEFAF5A0636}\
   ProgID]
   • "@"="IEHlprObj.IEHlprObj.1"

– [HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1]
   • "@"="IEHlprObj Class"

– [HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer]
   • "@"="IEHlprObj.IEHlprObj.1"

 Injection –  It injects the following file into a process: %SYSDIR%\ansb10.dll

    Process name:
   • explorer.exe


 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Description inserted by Petre Galan on Tuesday, November 23, 2010
Description updated by Petre Galan on Tuesday, November 23, 2010

Back . . . .