Home Malware Programs Dialers Inproc

Inproc

Posted: March 28, 2006

Inproc is a dialer that connects a compromised PC to the Internet by dialing premium rate phone numbers using a modem. Inproc also contacts certain remote web servers and may secretly download and install another dialer spyware without asking for user permission. The threat is bundled with some unsafe software. It also can get into the computer from many insecure web sites.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 egcomservice2.dll
    2 egcomservice_[XVS].dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareegdhtmlHKEY_LOCAL_MACHINESOFTWAREClassesEGCOMSERVICE.EGComSvcHKEY_LOCAL_MACHINESOFTWAREClassesEGCOMSERVICE.EGComSvc.1HKEY_LOCAL_MACHINESOFTWAREClassesEGCOMSERVICE2.EGComSvc2HKEY_LOCAL_MACHINESOFTWAREClassesEGCOMSERVICE2.EGComSvc2.1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}F3A257E6-FA04-4B30-A1B6-6B89EB814544AD9B275B-E42D-4C7F-9FFB-29B5FB81688BF8ACA5A0-060A-478A-8368-1407780D2251C13FA88A-D264-4BC8-92ED-52EB8181E209D7B59209-0ED9-4986-BD4A-527BE836C6B26AA93DF6-6757-4338-9087-F7601DE184022AEEAC34-FD74-4142-B891-4B05C0C03C87093F9CF8-0DE1-491C-95D5-5EC257BD4CA3

Related Posts

Loading...