Trojan.Ponmocup

Target:Windows
Aliases:Trojan.Rockfeller
Attributes:Payload: Hosts File
Technique: Rootkit UserSpace
What it means:
Trojan.Ponmocup may come bundled with the XvidCodecPack installer package. After installation it drops several malicious files onto the system including a rootkit to hide itself and modifies the host file. It then automatically launches porn web sites onto the infected system.

On execution, it drops following files,
  • %Temp% {random name}.tmp
  • %Temp% S_VideoCodecPack.exe
  • %Temp%~unins{random numbers}.bat
Trojan.Ponmocup creates the following directory and drops an un-installer file there,
  • %ProgramFiles%\VideoCodecPack
  • %ProgramFiles%\VideoCodecPack\Uninstall.exe
Following is the new process created.
  • %System%\{random file name}.exe
It may set filename as {perfproci, kbdcz1q, v7vga2}.exe etc.

Following dll file is created,
  • %System%\ntlanman8.dll
Name of dll file may change.

It modifies the host file:
  • %System%\drivers\etc\hosts
Contents of host file might have following hosts,
  • thepiratebay.org
  • www.thepiratebay.org
  • mininova.org
  • www.mininova.org
  • forum.mininova.org
  • blog.mininova.org
  • suprbay.org
  • www.suprbay.org
It modifies following registry keys:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\ipconfig
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\ipconfig\DEBUG
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
  • HKEY_LOCAL_MACHINE\SOFTWARE\qrjaslop
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\codecpackvideo
  • HKEY_CURRENT_USER\Software\qrjaslop
Note:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.


How can I avoid this:
To prevent the initial infection, a user or enterprise should apply security patches to operating systems, web browsers and other software in a timely manner, and run and maintain professional or freeware security tools such as anti-virus, personal firewall, and intrusion detection. Users should also avoid falling victim to social engineering attacks. Email attachments from unknown sources should not be opened, and users should not allow the installation of any program on their computer unless they trust the source of the program and know what the program is supposed to do.

What can I do:
The most reliable approach to clean your system is to restore it to a known clean restore point, or perform a new install of your system after backing up all your personal data. Other options include :
* Install or update your desktop security programs which may have removal capability for this threat. Often a user will need to boot into safe mode and then run a full scan to increase the chances of full removal.
* For the brave-hearted users, you can consult additional resources such as ThreatExpert, to perform a manual clean up. This is not recommended for anyone but an expert.