Alert level

Trojan:Win32/Camec.A

(?)

Encyclopedia entry
Updated: Apr 17, 2011  |  Published: Aug 31, 2010

Aliases
  • Trojan.Win32.BHO.akns (Kaspersky)
  • TR/BHO.akns (Avira)
  • Trojan.BhoSiggen.3775 (Dr.Web)
  • Trojan.Win32.BHO (Ikarus)

Alert Level (?)
Severe

Antimalware protection details
Microsoft recommends that you download the latest definitions to get protected.
Detection last updated:
Definition: 1.99.1050.0
Released: Mar 11, 2011
Detection initially created:
Definition: 1.89.660.0
Released: Aug 31, 2010


 

Summary

Trojan:Win32/Camec.A is a detection for a component of TrojanSpy:Win32/Camec.A. It disables User Account Control and updates another malware.


 

Symptoms

System changes
The following system changes may indicate the presence of this malware:
  • The presence of the following file:
    <system folder>\soundupkd.dll


 

Technical Information (Analysis)

Trojan:Win32/Camec.A is a detection for a component of TrojanSpy:Win32/Camec.A. It disables User Account Control and updates another malware.
Installation
Trojan:Win32/Camec.A is downloaded and installed by TrojanDownloader:Win32/Camec.A as a Browser Helper Object (BHO). It may be present in the computer as the following file:
 
  • <system folder>\soundupkd.dll
 
Note: <system folder> refers to a variable location that is determined by the malware by querying the Operating System. The default installation location for the System folder for Windows 2000 and NT is C:\Winnt\System32; and for XP, Vista, and 7 is C:\Windows\System32.
Payload
Disables User Account Control (UAC)
Trojan:Win32/Camec.A disables User Account Control (UAC) by modifying the following registry entry:
 
Sets value: "EnableLUA"
With data: "0x00000000"
In subkey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\
 
Updates other malware
Trojan:Win32/Camec.A connects to a remote server, where it checks if there is an update for TrojanSpy:Win32/Camec.A. If one is available, it downloads and installs it.
 
Analysis by Daniel Radu


 

Prevention



 

Recovery

To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
 
 
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.

Provide feedback