If AOL.Trojan is executed, it is possible for a hacker to perform any of the following actions:
- Reboot or shut down the computer
- Move the mouse pointer
- Enable and disable Ctrl+Alt+Delete
- Enable and disable the Start button
- Open or close the CD-ROM drive tray
- Read or delete AOL mail
- Hide or show the task bar
- Locate a member on AOL
- Monitor AOL Instant Messages
- Send a Instant Message
Most of these AOL Trojans are written in Visual Basic, which will not run on systems that do not have the Visual Basic run time libraries. Also, most of these AOL Trojans create copies of themselves in the following folders:
In most cases, the Trojan creates a registry value in one or more of these registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
These registry keys are common loading points to make sure that the Trojan is run when you start Windows.
Some also add lines to the Win.ini file or the System.ini file so that they run at startup; this works only under Windows 95/98/Me.
For information about common loading points, read one of these documents:
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":