Trojan:Win32/BHO.AM is a trojan component and is part of an adware application that uses a Web browser helper object (BHO) to display advertisements based on Web surfing habits. It may also download and install other potentially malicious files from remote servers.
Installation
This BHO component is installed by a dropper or adware application installer as one of the following files:
<system folder>\<random letters>.dll
<system folder>\helper.dll
Note - <system folder> refers to a variable location that is determined by the malware by querying the Operating System. The default installation location for the System folder for Windows 2000 and NT is C:\Winnt\System32; and for XP and Vista is C:\Windows\System32.
Once run, the registry is modified to execute the dropped component when a Web browser is launched.
Adds value: "(default)"
With data: "browser helper object"
To subkey: HKLM\SOFTWARE\Classes\AppID\{A0E1054B-01EE-4D57-A059-4D99F339709F}
Adds value: "AppID"
With data: "{a0e1054b-01ee-4d57-a059-4d99f339709f}"
To subkey: HKLM\SOFTWARE\Classes\AppID\main.DLL
Adds value: "(default)"
With data: "0"
To subkey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}
Adds value: "(default)"
With data: "browser helper object"
To subkey: HKLM\SOFTWARE\Classes\main.BHO.1
Adds value: "(default)"
With data: "{afd4ad01-58c1-47db-a404-fbe00a6c5486}"
To subkey: HKLM\SOFTWARE\Classes\main.BHO.1\CLSID
Adds value: "(default)"
With data: "browser helper object"
To subkey: HKLM\SOFTWARE\Classes\main.BHO
Adds value: "(default)"
With data: "{afd4ad01-58c1-47db-a404-fbe00a6c5486}"
To subkey: HKLM\SOFTWARE\Classes\main.BHO\CLSID
Adds value: "(default)"
With data: "main.bho.1"
To subkey: HKLM\SOFTWARE\Classes\main.BHO\CurVer
Adds value: "(default)"
With data: "browser helper object"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}
Adds value: "(default)"
With data: "main.bho.1"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\ProgID
Adds value: "(default)"
With data: "main.bho"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\VersionIndependentProgID
Adds value: "(default)"
With data: "<path and filename of Win32/BHO.AM>"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\InprocServer32
Adds value: "(default)"
With data: "{8e3c68cd-f500-4a2a-8cb9-132bb38c3573}"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\TypeLib
Adds value: "(default)"
With data: "main 1.0 type library"
To subkey: HKLM\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0
Adds value: "(default)"
With data: "0"
To subkey: HKLM\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\FLAGS
Adds value: "(default)"
With data: "<path and filename of Win32/BHO.AM>"
To subkey: HKLM\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\0\win32
Adds value: "(default)"
With data: "<path of Win32/BHO.AM>"
To subkey: HKLM\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\HELPDIR
Adds value: "(default)"
With data: "ibho"
To subkey: HKLM\SOFTWARE\Classes\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}
Adds value: "(default)"
With data: "{00020424-0000-0000-c000-000000000046}"
To subkey: HKLM\SOFTWARE\Classes\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}\ProxyStubClsid
Adds value: "(default)"
With data: "{00020424-0000-0000-c000-000000000046}"
To subkey: HKLM\SOFTWARE\Classes\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}\ProxyStubClsid32
Adds value: "(default)"
With data: "{8e3c68cd-f500-4a2a-8cb9-132bb38c3573}"
To subkey: HKLM\SOFTWARE\Classes\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}\TypeLib
Payload
Downloads Files
Win32/BHO.AM may download additional files from one of these servers, depending on variant:
-
searchersmart.com
-
clickzcompile.com
-
uatoolbar.com
Analysis by Patrik Vicol