Home Malware Programs Trojans Meheerwar

Meheerwar

Posted: March 28, 2006

Meheerwar is a trojan that changes the Internet Explorer start page, alters its web site history list and modifies other web browser settings. The spyware also creates numerous empty folders on the desktop and in the My Documents folder. These folders have English or Dutch names. Furthermore, Meheewar replaces the desktop wallpaper with a message in Dutch. The trojan may control the CD or DVD drive. It also swaps the left and right mouse buttons. Meheerwar runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 csrss.exe
    2 d.bmp
    3 del.exe
    4 dont delete me.exe
    5 msn.exe
    6 msnpaint.exe
    7 notedpad.exe
    8 open me.exe
    9 winfile.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[siteaddress1]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainWindowTitle=Warrior!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!ByMr.XHKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerTypedURLsurl[X]=[siteaddress2]HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunupdate=%System%winupdatecsrss.exe
Loading...