Home Malware Programs Dialers RasPro

RasPro

Posted: March 28, 2006

RasPro is a dialer that connects the compromised PC to the Internet by dialing a high-cost phone number using a modem. RasPro must be manually installed. It seems to be related with some Japanese web sites.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 775h1.ocx
    2 ras775.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTRAS775H1.Ras775h1Ctrl.1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}22F443F2-D84A-11D4-A8B7-00A0C9A49D9122F443F4-D84A-11D4-A8B7-00A0C9A49D9122F443F3-D84A-11D4-A8B7-00A0C9A49D9122F443F6-D84A-11D4-A8B7-00A0C9A49D9122F443F5-D84A-11D4-A8B7-00A0C9A49D91
Loading...