Home Malware Programs Browser Hijackers Wengs

Wengs

Posted: March 28, 2006

Wengs is a browser hijacker that changes the Internet Explorer default home page to the we.cn.gs web site. It monitors user Internet activity and collects certain information, which then is sent to predetermined remote servers. Wengs may also show flash animation and open some Chinese web resources. The threat has the ability to update itself via the Internet. Wengs runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 linmeimei.exe
    2 wupdate.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunWindowsUpdate=%System%wupdate.exe
Loading...