English
Deutsch
Español
Italian
Home
Virus Info
TR/BHO.G
Search
Home
Support
Solutions
Products
Downloads
Virus Info
Statistics
Phishing Worldmap
VDF History
Virus Science
Submit Sample
Security News
Viruses In the Wild
Company
Press
Partners
Newsletter
TR/BHO.G - Trojan
See also
Summary
Full description
Statistics
How would you rate this information?
Worthless
Excellent
Virus:
TR/BHO.G
Date discovered:
21/09/2006
Type:
Trojan
In the wild:
No
Reported Infections:
Low
Distribution Potential:
Low
Damage Potential:
Medium
Static file:
Yes
File size:
86.068 Bytes
MD5 checksum:
b144dcea0Cf4d0a28d0D810De47f5d90
VDF version:
6.36.00.44
IVDF version:
6.36.00.54
- Sat, 23 Sep 2006 14:26 (GMT+1)
General
Aliases:
• Mcafee: Vundo
• Kaspersky: Trojan.Win32.BHO.g
• Sophos: Troj/BHO-C
• Bitdefender: rojan.Vundo.M
Platforms / OS:
• Windows 95
• Windows 98
• Windows 98 SE
• Windows NT
• Windows ME
• Windows 2000
• Windows XP
Side effects:
• Registry modification
• Steals information
Registry
It registers a browser helper object (BHO) by adding the following key:
– HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{B7672BAF-E9A3-49B6-86B2-C81719A18A4C}
The following registry key is added:
– HKCR\CLSID\{B7672BAF-E9A3-49B6-86B2-C81719A18A4C}\InprocServer32
• "(Defaulat)"=
%executed file%
• "ThreadingModel"="Both"
Stealing
– A logging routine is started after a website is visited:
• allyoursearch.com thefreedictionary.com searchfeed.com www.neon.org.uk
www.sensis.com.au slotch.com mygeek.com clearsearch.com
search.gohip.com usseek.com findwhat.com websearch.com revquest.com
7search.com ditto.com mysearch.myway.com mywebsearch.com
destinationadult.com instafinder.com uk.overture.com exactsearch.net
findsearch.net perfectnav.com scoutcrawl.com genieknows.com
navisearch.net what2find.com sirsearch.com crawlbar.com overture.com
inquire.com netster.com www.grip.com www.ukindex.co.uk lb1.netster.com
64.225.154.135 zeal.com seeq.com uk.searchengine.com url.searchuk.com
www.excite.co.jp search.dmoz.org www.goclick.com wikipedia.org
search.about.com galaxysearch.com wesearchall.com terms= sex.com
www.london-pages.co.uk vachercher.lycos.fr search.netscape.com
search.netzero.net search.lycos.co.uk cgi.search123.com
search.asiaco.com query.nytimes.com search.aol.co.uk search.lycos.com
www.250000.co.uk search.aol.com suche.lycos.de zoek.lycos.nl
vivisimo.com kanoodle.com comcast.net hotbot.com jayde.com mamma.com
mirago.co.uk mirago.de searchmiracle.com coolwebsearch.com
search.looksmart.com www.infoseek.co.jp dogpile.com sqwire.com
vaclick.epilot.com searchscout.com apps5.oingo.com 66.220.17.157
fr.search.yahoo.com au.search.yahoo.com uk.search.yahoo.com
kr.search.yahoo.com ca.search.yahoo.com tw.search.yahoo.com
de.search.yahoo.com hk.search.yahoo.com search.yahoo.co.jp
search.yahoo.com search.sympatico.msn.ca search.earthlink.net
search.wanadoo.co.uk search.xtramsn.co.nz www.recherche.aol.fr
www.google.com.tw search.msn.com.hk www.google.com.hk
www.google.com.au au.altavista.com fr.altavista.com de.altavista.com
nz.altavista.com nl.altavista.com uk.altavista.com search.msn.co.uk
kr.altavista.com www.google.co.uk www.google.co.kr www.google.co.nz
www.google.co.jp search.daum.net emetasearch.com search.msn.com
shoprogers.com reference.com web.ask.co.uk go.google.com alltheweb.com
search.msn.fr gigablast.com altavista.com google.com.mx goguides.org
google.co.uk cp.ah-ha.com web.ask.com wisenut.com s.teoma.com
google.com google.be bbc.co.uk google.fr google.it google.ca google.de
alexa.com google.es
File details
Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
See a brief description
here
.
Description inserted by Bogdan Iliuta on Thu, 12 Oct 2006 11:15 (GMT+1)
Description updated by Bogdan Iliuta on Mon, 30 Oct 2006 15:10 (GMT+1)
»
About Malware
»
About Phishing
»
Viruses In the Wild
« back
Print this page
W32/Elkern.C
TR/Crypt.CFI.Gen
Worm/KillAV.GR
Worm/Mytob.AP
Worm/Mytob.AD
TR/Crypt.PEPM.Gen
TR/Vundo.ewz.9
TR/Monderb.318720
Worm/IrcBot.39673.1
TR/PSW.Steam.DU
Get comfortable up to the minute info from Avira as
Detects and removes the following malware and its variants:
Worm/Sober.J
Worm/Sober.P
Worm/Sober.Y
W32/Stanit.A
Worm/NetSky.AA
Worm/NetSky.B.1
Worm/NetSky.C
Worm/Netsky.D.Dam
Worm/NetSky.P
Worm/NetSky.X
Worm/Mytob.IN.2
Worm/Mytob.KS
TR/Spy.Banker.AATZ
TR/Spy.Banker.AATZ.1
TR/Spy.Banker.AATZ.2
TR/Spy.Banker.AATZ.3
Download here
Click
here
to get the panel...
© 2008 Avira GmbH
Copyright
Privacy
Sitemap
Feedback
Imprint
FAQ
Contact