Home Malware Programs Dialers ICcontrol

ICcontrol

Posted: March 28, 2006

ICcontrol, also known as Internet Connection Control, is a dialer that connects a compromised PC to the Internet by dialing high-cost phone numbers using a modem. The threat also enables a proxy and creates a computer service. ICcontrol is bundled with some ad-supported applications and certain spywares. It automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 icc.dll
    2 iccontrol.exe
    3 madchook.dll
    4 mc2a.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}4D36E96D-E325-11CE-BFC1-08002BE10318000UserInit=S7=2405158BCD9-12AB-4301-8F5B-D4911E2AF3FAiccontrolHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsProxyEnable=1HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsProxyOverride=localHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsProxyServer=[proxyaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunICcontrolHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallICcontrolHKEY_LOCAL_MACHINESYSTEMCurrentControlSetHardwareProfilesCurrentSoftwareMicrosoftwindowsCurrentVersionInternetSettingsProxyEnable=1

Related Posts

Loading...