AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 03, 2008, 06:54:03 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4767 Members
Latest Member: CleosMM
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: Trojan.Hugesot 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Trojan.Hugesot  (Read 574 times)
TJ
Tech Team
Hero Member
********
Offline Offline

Posts: 136



View Profile
Trojan.Hugesot
« on: September 19, 2005, 11:31:02 PM »

Trojan.Hugesot is a Trojan horse that downloads remote files and attempts to start a command shell on the compromised computer.

Once executed, Trojan.Hugesot performs the following actions:

   1. Adds the value:

      "sysdll" = "[TROJAN FILE NAME]"

      to the following registry subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

      so that it is executed every time Windows starts.

   2. Connects to following URL and downloads configuration data:

      [http://]news.hugesoft.org/[REMOVED]/interl.html

   3. Attempts to perform the following actions:

          * Download and execute files
          * Upload files
          * Start a command shell

   4. Downloads a file from following URL and save it as %CurrentFolder%\syshost.exe:

      [http://]news.hugesoft.org/[REMOVED]/interl.gif

      Note: %CurrentFolder% is a variable that refers to the folder where the risk was originally executed.

   5. Attempts to contact the following server to receive further commands from a remote attacker:

      [http://]news.hugesoft.org/[REMOVED]/start.asp

   6. Sends system information to the following server:

      [http://]news.hugesoft.org/[REMOVED]/auto.asp

REMOVAL INSTRUCTIONS
See: http://securityresponse.symantec.com/avcenter/venc/data/trojan.hugesot.html

To delete the value from the registry
   1. Click Start > Run.
   2. Type regedit
   3. Click OK.
   4. Navigate to the subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

   5. In the right pane, delete the value:

      "sysdll" = "[TROJAN FILE NAME]"

   6. Exit the Registry Editor.
Logged
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: Trojan.Hugesot « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!