Home Malware Programs Trojans Havedo

Havedo

Posted: March 28, 2006

Havedo is a trojan that attempts to corrupt Microsoft Visual FoxPro databases or other related data.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cmd.exe
    2 cmd.lnd
    3 iexplorex.dll
    4 project.pjx.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}37125E31-AD55-4F7B-BF6F-A17A20953945InprocServer32(Default)=%Windir%iexplorex.dllHKEY_LOCAL_MACHINESoftwareMicrosoftHavedoHKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHiddenSHOWALLCheckedValue=0
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}37125E31-AD55-4F7B-BF6F-A17A20953945
Loading...