Home Malware Programs Browser Hijackers Chorus

Chorus

Posted: March 28, 2006

Chorus is a browser hijacker that changes Internet Explorer default home and search pages to undesirable web sites and adds several commercial bookmarks to the web browser's Favorites list. The spyware doesn't have any additional functionality or dangerous payload. Chorus automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 htmlsync.exe
    2 isystem.exe
    3 ldriver.exe
    4 zlibc.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchBar=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchPage=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainUseCustomSearchURL=1HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearchURL=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunldriverHKEY_CURRENT_USERSoftwareMicrosoftWindowsNTCurrentVersionWindowsRun\%Windows%htmlsync.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainDefault_Page_URL=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainDefault_Search_URL=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainSearchPage=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainStartPage=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunisystemHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWindowsRun\%Windows%zlibc.exe
Loading...