Home Malware Programs Adware Slagent

Slagent

Posted: May 15, 2006

Slagent is an adware program that contacts its controlling server to display advertisements. Slagent does not notify the user after initial installation and can download and execute arbitrary files on the computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 2_mslagent.dll
    2 2_navpmc.dll
    3 4w64lz577k.exe
    4 acknowledged.mc2
    5 aonmkqph.exe
    6 compmanagerpersist.mc2
    7 msklive.dll
    8 mslagent.exe
    9 mslagent_.exe
    10 navigation.exe
    11 navipersist.mc2
    12 navipromo.mc2
    13 navpmc.exe
    14 orderpersist.mc2
    15 setup.exe
    16 setup_hp.exe
    17 setup_hp3.exe
    18 setupapi.exe
    19 setupgen.exe
    20 setupod.exe
    21 slagent-a.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}19068197-6f58-4e8a-8007-7155a68ca967\programmableHKEY_CLASSES_ROOT\mslagent.3HKEY_CLASSES_ROOT\mslagent.3.1HKEY_CLASSES_ROOT\mslagent.8HKEY_CLASSES_ROOT\mslagent.8.1HKEY_CLASSES_ROOT\navipromo.egnaviscoringHKEY_CLASSES_ROOT\navipromo.egnaviscoring.1d7a82a12-05f5-42d8-b30d-6ef995075d2d\programmable
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}d55589f7-2879-47e8-9c66-27de6477a814ba49bd6a-039c-428e-af33-8c1288d75a7b82c0673c-f1d1-47ba-b904-ab0de82300bc7acd434e-3dbb-415f-9d04-0c4ed32de4035630b768-1c09-4105-9e03-e35985e36b0b75a603e7-8bb7-4272-abbe-9846ff1241c152bcfe5a-2015-4ab2-83f0-80903a38d9a64a6fa2eb-f381-4503-87d0-be4cc57deb8e008db894-99ed-445d-8547-0e7c9808898d

Related Posts

Loading...