Threat behavior
BrowserModifier:Win32/AdultLinksQbar adds links to adult content Web sites to the Internet Explorer Favorites menu and user desktop. AdultLinksQbar may alter the Internet Explorer search page.
Installation
Win32/AdultLinksQbar is installed via ActiveX control hosted on external Web servers. Once installed, Win32/AdultLinksQbar may be present as the following files:
<system folder>\insqcb.ins
<system folder>\qabar.dll
- <system folder>\allch.dll
<system folder>\llch.dll
%APPDATA%\qcbar
%USERPROFILE%\application data\qcbar.dll
After installation, the following Web browser links may be present:
<Internet Browser Favorites>\adultlinks
<Internet Browser Favorites>\adultsearch
<Internet Browser Favorites>\sports&&games
<Internet Browser Favorites>\viagra+health
<Internet Browser Favorites>\virility+health
<Internet Browser Favorites>\links\adultlinks
<Internet Browser Favorites>\links\adultsearch
<Internet Browser Favorites>\links\sports&&games
<Internet Browser Favorites>\links\viagra+health
<Internet Browser Favorites>\links\virility+health
The following subkeys may be created within the registry:
HKEY_CLASSES_ROOT\allch.ieobj
HKEY_CLASSES_ROOT\allch.ieobj.1
HKEY_CLASSES_Root\CLSID\{242ca913-1637-4f74-9729-ea349af3ecac}
HKEY_CLASSES_Root\CLSID\{5c015aa7-3392-4044-90cc-8e95019cfff1}
HKEY_CLASSES_Root\CLSID\{60381d4b-8129-449a-a5f2-5417ad0571cc}
HKEY_CLASSES_Root\CLSID\{6d7d135e-f7c2-4a27-a87c-c0dfeb3a628f}
HKEY_CLASSES_Root\CLSID\{c02ee3a0-1881-419f-a5ed-737223463292}
HKEY_CLASSES_Root\CLSID\{d02ee3a0-1881-419f-a5ed-737223463292}
HKEY_CLASSES_Root\CLSID\{d1320cbb-403d-483d-ae9a-688960a96977}
HKEY_CLASSES_Root\CLSID\{ed7d1356-f7c2-4a27-a87c-c0dfeb3a628f}
HKEY_CLASSES_ROOT\Interface\{242ca913-1637-4f74-9729-ea349af3ecac}
HKEY_CLASSES_ROOT\Interface\{d1320cbb-403d-483d-ae9a-688960a96977}
HKEY_CLASSES_ROOT\Interface\{ed7d1356-f7c2-4a27-a87c-c0dfeb3a628f}
HKEY_CLASSES_ROOT\Qabar
HKEY_CLASSES_ROOT\Qabar.1
HKEY_CLASSES_ROOT\Qabar.adultsearch
HKEY_CLASSES_ROOT\Qabar.adultsearch.1
HKEY_CLASSES_ROOT\Qcbar
HKEY_CLASSES_ROOT\Qcbar.1
HKEY_CLASSES_ROOT\Typelib\{5c015aa7-3392-4044-90cc-8e95019cfff1}
HKEY_CLASSES_ROOT\Typelib\{60381d4b-8129-449a-a5f2-5417ad0571cc}
HKEY_CLASSES_ROOT\Typelib\{765e6b09-6832-4738-bdbe-25f226ba2ab0}
HKEY_CLASSES_ROOT\Typelib\{c02ee3a0-1881-419f-a5ed-737223463292}
HKEY_CURRENT_USER\Software\linkzz
HKEY_CURRENT_USER\Software\qcbar
HKEY_LOCAL_MAchine\Software\classes\clsid\{dd1bca06-f674-424d-a08e-42da97c4d5dd}
HKEY_LOCAL_MAchine\Software\classes\interface\{d1320cbb-403d-483d-ae9a-688960a96977}
HKEY_LOCAL_MAchine\Software\classes\interface\{6d7d135e-f7c2-4a27-a87c-c0dfeb3a628f}
HKEY_LOCAL_MAchine\SoftWARE\Classes\IBSBand.AdultSearch.1
HKEY_LOCAL_MAchine\SoftWARE\Classes\IBSBand.AdultSearch
HKEY_LOCAL_MAchine\Software\classes\qabar
HKEY_LOCAL_MAchine\Software\classes\qabar.1
HKEY_LOCAL_MAchine\Software\classes\qabar.adultsearch
HKEY_LOCAL_MAchine\Software\classes\qabar.adultsearch.1
HKEY_LOCAL_MAchine\Software\classes\qabar.adultsearch\clsid
HKEY_LOCAL_MAchine\Software\classes\qabar.adultsearch\curver
HKEY_LOCAL_MAchine\Software\classes\qabar\clsid
HKEY_LOCAL_MAchine\Software\classes\qabar\curver
HKEY_LOCAL_MAchine\SoftWARE\Classes\QcBar.1
HKEY_LOCAL_MAchine\SoftWARE\Classes\QcBar
HKEY_LOCAL_MAchine\Software\classes\typelib\{d02ee3a0-1881-419f-a5ed-737223463292}
HKEY_LOCAL_MAchine\Software\microsoft\code store database\distribution units\{765e6b09-6832-4738-bdbe-25f226ba2ab0}
HKEY_LOCAL_MAchine\Software\microsoft\code store database\distribution units\{965e6b07-6832-4738-bdbe-25f226ba2ab0}
HKEY_LOCAL_MAchine\Software\microsoft\code store database\distribution units\{965e6b07-6832-4738-bdbe-25f226ba2ab0}
HKEY_LOCAL_MAchine\Software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/qabar.dll\{965e6b07-6832-4738-bdbe-25f226ba2ab0}
HKEY_LOCAL_MAchine\SoftWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/QcBar.dll
HKEY_LOCAL_MAchine\Software\qcbar
AdultLinksQbar may alter the Internet Explorer search page by altering data stored in the following registry subkeys:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
HKEY_LOCAL_MAchine\Software\microsoft\internet explorer\toolbar
Analysis by Aaron Hulett
Prevention