This threat has been renamed from Trojan.Dnschanger to Trojan.Flush.K.
Trojan.Flush.K is a Trojan horse that modifies the DNS server settings on the compromised computer and redirects the browser to potentially malicious Web sites.
When the Trojan is executed, it creates the following folders:
- %ProgramFiles%\DirectVideo
- %UserProfile%\Start Menu\Programs\DirectVideo
The Trojan then creates the following files:
- %UserProfile%\Local Settings\Temp\svchost.exe
- %UserProfile%\Local Settings\Temp\step1.exe
- %UserProfile%\Local Settings\Temp\step2.exe
- %System%\kd???.exe
- %ProgramFiles%\DirectVideo\Uninstall.exe
- %UserProfile%\Start Menu\Programs\DirectVideo\Uninstall.lnk
The Trojan hides the following files using a user mode rootkit:
- %System%\kd???.exe
- %UserProfile%\Local Settings\Temp\step2.exe
Next, the Trojan creates the following registry entry, which is protected against removal or modification, and ensures that it executes whenever Windows starts:
%HKEY_LOCAL_MACHINE%\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"System" = "kd???.exe"
The Trojan also creates the following registry subkeys:
%HKEY_ALL_USERS%\Software\DirectVideo
%HKEY_CLASSES_ROOT%\DirectVideo
%HKEY_CLASSES_ROOT%\DirectVideo\CLSID
%HKEY_LOCAL_MACHINE%\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectVideo
The Trojan then creates the following registry entries:
HKEY_CLASSES_ROOT\DirectVideo\CLSID\"Default" = "{6BF52A52-394A-11D3-B153-00C04F79FAA6}"
HKEY_ALL_USERS\Software\DirectVideo\"Default" = "%ProgramFiles%\DirectVideo"
HKEY_ALL_USERS\Software\DirectVideo\"Start Menu Folder" = "DirectVideo"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectVideo\"DisplayIcon" = "%ProgramFiles%\DirectVideo\Uninstall,0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectVideo\"DisplayName" = "DirectVideo"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectVideo\"InstallLocation" = "%ProgramFiles%\DirectVideo"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectVideo\"NoModify" = "0x00000001"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectVideo\"NoRepair" = "0x00000001"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectVideo\"UninstallString" = "%ProgramFiles%\DirectVideo\Uninstall.exe"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\[RANDOM CLSID]\"DhcpNameServer" = "85.255.115.21,85.255.112.91"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\[RANDOM CLSID]\"NameServer" = "85.255.115.21,85.255.112.91"
Next, the Trojan checks for the presence of the following file:
%UserProfile%\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk
If the above file exists, the Trojan then creates the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\[RANDOM CLSID]\"DhcpNameServer" = "85.255.115.21,85.255.112.91"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\[RANDOM CLSID]\"NameServer" = "85.255.115.21,85.255.112.91"
Next, the Trojan executes the following Windows commands to update the changes made to the configuration of the compromised computer:
- ipconfig.exe/flushdns
- ipconfig.exe/registerdns
- ipconfig.exe/dnsflush
- ipconfig.exe/renew
- ipconfig.exe/renew_all
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":