Sophos

Troj/Favadd-D

Aliases
  • Trojan.Win32.Favadd.d
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 10 November 2004 10:00:07 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj\Favadd-D is a Trojan that adds several shortcuts to the Favorites menu in Internet Explorer pointing to crack and serial websites. The Trojan will also add a button to the Internet Explorer toolbar that goes to www.crackspider.com.

Troj/Favadd-D also will replace the Internet Explorer search pages with its own. The Trojan will then start Internet Explorer with the start page of www.crackspider.net. It leaves behind a harmless file called crcspider.ico in the Windows folder.

Troj\Favadd-D may create a new folder called "cracks" in the favorites folder with the following shortcuts and descriptions:

http://www.thebugs.ws "! TheBUGS.ws - Security Related Portal"
http://crackspider.net "!! CrackSpider.NET - Cracks search engine"
http://mscracks.com "mscrack.com - Cracks, serial numbers..."
http://allseek.info "allseek.info - The Underground portal"
http://www.crackspider.de "CrackSpider.DE - Cracks search engine"
http://www.crackspider.us "CrackSpider.US - Cracks search engine"
http://www.crackportal.com "CrackPortal.com - Cracks, serial number"
http://astalavista.thebugs.ws "Astalavista - Cracks search engine"
http://www.crackway.com "CrackWay.com - Since 2001 cracks arhive"
http://keygen.us "KeyGen.US - Keygens, patches, crackz..."
http://icracks.net "iCracks.net - Keygens, patches, crackz."
http://anycracks.com "anyCracks.com - Keygens, patches, crack"
http://bestserials.com "bestserials.com - Best serials"

Troj\Favadd-D may create the following registry entries:

HKCU\Software\Microsoft\Internet Explorer\Extensions\
(10954C80-4F0F-11d3-B17C-00C0DFE39736)
ButtonText = "Search cracks at CrackSpider.NET"

HKCU\Software\Microsoft\Internet Explorer\Extensions\
(10954C80-4F0F-11d3-B17C-00C0DFE39736)
MenuText = "Search cracks at CrackSpider.NET"

HKCU\Software\Microsoft\Internet Explorer\Extensions\
(10954C80-4F0F-11d3-B17C-00C0DFE39736)
MenuStatusBar = "Search cracks at CrackSpider.NET"

HKCU\Software\Microsoft\Internet Explorer\Extensions\
(10954C80-4F0F-11d3-B17C-00C0DFE39736)
ClSid = (1FBA04EE-3024-11d2-8F1F-0000F87ABD16)

HKCU\Software\Microsoft\Internet Explorer\Extensions\
(10954C80-4F0F-11d3-B17C-00C0DFE39736)
Default Visible = "Yes"

HKCU\Software\Microsoft\Internet Explorer\Extensions\
(10954C80-4F0F-11d3-B17C-00C0DFE39736)
Exec = "http://crackspider.net/"

HKCU\Software\Microsoft\Internet Explorer\Extensions\
(10954C80-4F0F-11d3-B17C-00C0DFE39736)
HotIcon = "<windows>\crcspider.ico"

HKCU\Software\Microsoft\Internet Explorer\Extensions\
(10954C80-4F0F-11d3-B17C-00C0DFE39736)
Icon = "<windows>\crcspider.ico"

HKCU\Software\Microsoft\Internet Explorer\Search
SearchAssistant = http://crackspider.net/

HKCU\Software\Microsoft\Internet Explorer\Main
Search Bar = "http://crackspider.net/"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer