Home Malware Programs Trojans Myftu

Myftu

Posted: March 28, 2006

Myftu is a trojan designed to register its victim to Japanese porn service without asking for his permission. The trojan can show a message in Japanese related to a porn service. It also scans the computer for e-mail addresses, collects them and sends to predefined web servers. Myftu modifies the Windows registry and drops infected files into the C:Program Files folder. It doesn't compromise the computer, but violates user privacy and must be removed as soon as possible.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 freemovies.exe
    2 mch.exe
    3 movies.exe
    4 movload.exe
    5 mv99.exe
    6 playdvdmovie.exe
    7 playmovie.exe
    8 update.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftware99MCHKEY_CURRENT_USERSoftwareCRBBHKEY_CURRENT_USERSoftwareMCHHKEY_CURRENT_USERSoftwareMCTHKEY_CURRENT_USERSoftwareMV99HKEY_CURRENT_USERSoftwarePMCHKEY_CURRENT_USERSoftwareSerialBzsHKEY_CURRENT_USERSoftwareSerialXmHKEY_CURRENT_USERSoftwareSerialcHKEY_CURRENT_USERSoftwareoncDVD
Loading...