Home Malware Programs Trojans Orifice2K.plugin

Orifice2K.plugin

Posted: May 28, 2010

Orifice2K.plugin is a malicious Trojan that may represent security risk for the infected computer. Orifice2K.plugin uses sneaky rootkit-specific techniques designed to hide the software presence in the system. Orifice2K.plugin blocks access to security websites and changes the NDS server options to a fixed IPS. Orifice2K.plugin spreads by copying itself to all removable drives so that it executes whenever the drive is accessed.

Aliases

VirTool:Win32/Mader.C (Microsoft)
Win-Trojan/Xema.variant (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\_sv_.exe
    2 %System%\drivers\_sv_.sy

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\_sv_][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\_sv_][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ntfscore\Enum][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ntfscore\Security][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ntfscore][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\_sv_][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\_sv_][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\_sv_][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ntfscore\Enum][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ntfscore\Security][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ntfscore][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_sv_]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
Loading...