Home Malware Programs Trojans Harnig

Harnig

Posted: March 28, 2006

Harnig is a trojan designed to secretly download and install numerous adware spywares, dialers, backdoors and other trojans.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 desktop.exe
    2 dial32.exe
    3 dkdial.exe
    4 kl.exe
    5 mstasks1.exe
    6 mstasks2.exe
    7 paytime.exe
    8 seksdialer.exe
    9 system.exe
    10 system32.dll
    11 tool[X].exe
    12 toolbar.exe
    13 wintime.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsMinLevel=CodeDownloadHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsSafetyWarningLevel=SucceedSilentHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsSecurity_RunActiveXControls=0x01000000HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsSecurity_RunScripts=0x01000000HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsTrustWarningLevel=NoSecurityHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwintimeHKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionInternetSettingsMinLevel=CodeDownloadHKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionInternetSettingsSafetyWarningLevel=SucceedSilentHKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionInternetSettingsSecurity_RunActiveXControls=0x01000000HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionInternetSettingsSecurity_RunScripts=0x01000000HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionInternetSettingsTrustWarningLevel=NoSecurity
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}0A323FA1-38DE-44EC-B2FA-4002183C143E

Related Posts

Loading...