Home Malware Programs Malware CXmal/DNSCha-A

CXmal/DNSCha-A

Posted: April 27, 2012

Threat Metric

Ranking: 2,557
Threat Level: 2/10
Infected PCs: 61,040
First Seen: April 27, 2012
Last Seen: October 16, 2023
OS(es) Affected: Windows

CXmal/DNSCha-A detects registry modification made by a class of DNSChanger Trojans such as Troj/DNSChan-A. CXmal/DNSCha-A will only start from a full system scan, either scheduled or on-demand. If your endpoint is not set up to use DHCP, manual cleanup, changing the DNS server settings, is required. You should manually change your DNS settings You refer to the proper server for your organization or ISP. CXmal/DNSCha-A may reset the DNS name server setting on windows computer for various network interfaces on the host computer.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\\NameServerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run hgqhp.exe = C:\WINDOWS\system32\hgqhp.exeHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2861B0F9-F1E8-4A1A-B9D5-08FB3E595B28} NameServer: 85.255.115.101,85.255.112.115HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{92A284E9-43B2-406E-A24E-FCB05ACBAD8B} NameServer: 85.255.115.101,85.255.112.115

Additional Information

The following URL's were detected:
ckk.ai

One Comment

  • Nisha says:

    When a Cleaner is use it will detect bokren files in the registry though when a program is install it makes diferent copies in diferent sub folders of the registry so you can manually look for them if you know the file name or program name in the registry window . open registry editor by typing regedit in the registry window click on computer to select it and in the tab edit click Find and type the name of the program or file tyopu are looking for the when you delete press F3 to continue to look furter more until no more copies of the file or program is found, though I must tell you this is very delicate process and you should know exactly what you R looking for otherwise you may make it worse. so I sujest if the CCleaner have a way to back up the registry . do it before you start deletions of registry values.

Loading...