Home Malware Programs Trojans Oxtic

Oxtic

Posted: March 28, 2006

Oxtic is a trojan designed to take annoying, but not very dangerous actions on the compromised computer. The spyware can shutdown a PC, blay beeping sounds using the PC speaker, swap mouse buttons or launch several instances of one application. Oxtic disables essential Windows computer tools including the Task Manager and the Registry Editor. The trojan is loaded every time an executable file is run.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 svchost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTexefileShellOpencommand=%Windir%svchost.exe%1%*HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableRegistryTools=1HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr=1HKEY_LOCAL_MACHINESOFTWAREClassesexefileShellOpencommand=%Windir%svchost.exe%1%*
Loading...