Home Malware Programs Malware HubSafe

HubSafe

Posted: March 28, 2006

HubSafe is a spyware that claims to be a parental tool. It asks the user to provide some confidential information and then sends it out. HubSafe also installs a web browser plugin and creates a desktop shortcut with Korean characters. It doesn't carry any destructive payload. The threat is able to silently update itself via the Internet. It automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 hscontrol.dll
    2 hssvc.exe
    3 hubfilter.dll
    4 hubsafe.exe
    5 hubupdate.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareLocalAppWizard-GeneratedApplicationsHubSafeHKEY_LOCAL_MACHINESOFTWAREClassesHSControl.HSCtrlHKEY_LOCAL_MACHINESOFTWAREClassesHubFilter.HubBhoHKEY_LOCAL_MACHINESOFTWAREClassesHubFilter.HubBho.1HKEY_LOCAL_MACHINESOFTWAREHubCoreaHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunhssvc
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}C59329B9-26F3-41b7-AE08-1B667C45D716F0ECEE0D-B98C-4089-A49D-5525390E9C4F47EDACAE-B627-4A95-BBE9-A98FD3245CEFEAECE877-9840-49D5-B887-9F73CA7A06AD05D7ACBE-13B7-4294-A5E6-9D0013D6D1A0F5ADCBFA-D196-4720-9FCD-F7EDE518E33D0001E20D-F6AE-4A9F-9012-C925ED691FBB

Related Posts

Loading...