Here are the screen shots of message boxes displayed by the virus when Orkut website is opened or Firefox is launched:


Svchost.exe is nothing but renamed AutoHotKey program! Mozban creates a folder named heap41a in the root drive, and files listed below:2.mp3
drivelist.txt
Icon.ico
offspring
reproduce.txt
script1.txt
std.txt
svchost.exeAnd, the folder offspring contains:
MicrosoftPowerPoint.exe
autorun.infFiles
std.txt, script1.txt and reproduce.txt contain AutoHotKey scripts, which are executed by svchost.exe (renamed AutoHotKey).Here are the screen shots Jotti Malware Scan results of files - svchost.exe and MicrosoftPowerPoint.exe - dropped by the virus:

0 comments:
Post a Comment