Home Malware Programs Trojans Hanmon

Hanmon

Posted: March 28, 2006

Hanmon is a trojan, which injects malicious code into legitimate processes. It contacts a predetermined remote host in order to receive additional instructions. Currently Hanmon does not perform any malicious actions. However, its activity may severely degrade overall computer performance. The trojan automatically runs as a service on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 dmcpyt.dll
    2 tstdmc.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionSvchostdmon=diskmon32HKEY_LOCAL_MACHINESYSTEMCurrentControlSetENUMROOTLEGACY_DISKMON32HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesdiskmon32HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceslanmanworkstationDependOnService=diskmon32
Loading...