SpywareGuide powered by Actiance Security Labs
Search SpywareGuide Database & Site
Home Access the Guide
List of Products List of Companies List of Categories
Tools
X-RayPC
Terms and Definitions
 
Full Name:
AntiBTC Websearch   Read More
Type: Trojan
Also Known as: Ataka IEPatch.PWL.Trojan Trojan:Win32/AntiBTC TROJ_ANTIBTC.A TR/Ataka Win/Po-zdrawi.28416.trojan Ataka-AntiBTC Trojan.Win32.AntiBTC Trojan.Win32.AntiBTC.a
SG Index: 2 [Explain]
Category Description: Trojans are malicious applications that pose themselves as legitimate software in order to trick users to install them. Once on the victim's machine, it may run any number of malicious process to steal vital information or inflict damage to other software.
Comment: From Viruslist.com
This Trojan arrives as an executable files (we got it named IE0199.EXE). When it is run, it extracts two files from its body (MPREXE.DLL and SNDVOL.EXE) and copies them to the Windows system directory. Note: the MPREXE.EXE executable file (not a DLL) is one of the standard Windows files.

The Trojan then registers the MPREXE.DLL file in the system to force the system to run this file upon each reboot. The registration is done depending on the Windows version either in the system registry, or in the SYSTEM.INI file in [boot] section in the "drivers=" string. The MPREXE.DLL file is pointed as auto-executed.

When executed, the MPREXE.DLL file just executes the SNDVOL.EXE file and exits. The SNDVOL.EXE file enables auto-dialing by changing the system registry Internet options, randomly selects one of three Bulgarian Web servers (www.btc.bg, www.infotel.bg, ns.infotel.bg), connects them and sleeps for some time. The Trojan does not perform any other actions.

   

Click here to leave feedback for this product

Recent Modifications
2012-5-10  NetSpy
2012-5-1  Unclassified Adware/Spyware
2012-4-11  Adult Networks/Services
2012-4-11  CoolWebSearch
2012-3-13  Misc. Exploits
2012-2-24  Zango Times
2012-2-24  About Blank
2012-1-30  HostSeeker Toolbar
2012-1-13  2000Cracks
2012-1-13  7AdPower Dialer
 
Company  | Site and Spyware FAQ
© Copyright 2003-2011, Actiance, Inc. All rights reserved.   Privacy Policy