Home Malware Programs Dialers HotPleasure

HotPleasure

Posted: March 28, 2006

HotPleasure is a dialer that connects a compromised PC to the Internet by dialing a high-cost phone number using a modem. The threat provides access to pornographic resources. It also modifies web browser's default security settings. HotPleasure can get into the computer while visiting some malicious web sites. Some dialer variants must be manually installed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 hot_pleasure.exe
    2 pleasure2.exe
    3 pleasure2update.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT.cntyHKEY_CLASSES_ROOTMIMEDatabaseContentTypeapplication/x-cnty-2HKEY_CLASSES_ROOTcnty2HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun[randomname]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunpleasure2HKEY_USERS.DefaultSoftwareNetscapeNetscapeNavigatorSuffixesapplication/x-cnty-2HKEY_USERS.DefaultSoftwareNetscapeNetscapeNavigatorUserTrustedExternalApplications[pathtoafile]HKEY_USERS.DefaultSoftwareNetscapeNetscapeNavigatorViewersapplication/x-cnty-2
Loading...