Hi Pranay,
We treated this malcode here:
http://forum.avast.com/index.php?topic=37513.0Was yours also related to BBOX Trial Client DLL :
http://www.processlibrary.com/directory/files/vboxs430/ obviously this threat was covered by a Packer which were usually used by hacker
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following registry elements have been created:
# HKEY_CURRENT_USER\_reg\
* shell = "c:\windows\system32\rundll32.exe" "c:\windows\system32
\shell32.dll",control_rundll "c:\docume~1\admini~1\locals~1\temp
\dat15.tmp"
# HKEY_LOCAL_MACHINE\software\classes\clsid\{e25c29ab-12b9-4523-a53c-324b5fba648c}\inprocserver32\
* (default) = c:\docume~1\admini~1\locals~1\temp\dat15.tmp
* threadingmodel = apartment
The following registry elements have been changed:
# HKEY_CURRENT_USER\sessioninformation\
* programcount = 2
# HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\desktop\
* mrulist = [binary data]
* rxmru = [binary data]
# HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\desktop\
* mrulist = [binary data]
* rxmru = [binary data]
* sysfile = c:\documents and settings\administrator\local settings\temp
\2.exe
The following registry elements have been deleted:
# HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\desktop\
* sysfile = c:\documents and settings\administrator\local settings\temp
\2.exe
Symptoms
Symptoms -
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.
Considerations there may be variants,
polonus