Trojan:Win32/BHO.LI is a trojan that runs as a Browser Helper Object (BHO) in Internet Explorer under the name "CableRouting".
Installation
Trojan:Win32/BHO.LI may be installed as a BHO by a dropper, an installer or when visiting a malicious Web site that executes an installation process or routine.
After installation, the trojan makes a number of registry modifications:
Adds value: "TrapPollTimeMilliSecs"
With data: "15000"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters
Adds value: "(default)"
With data: "cablerouting class"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18CB1A7B-94CD-4582-8022-ADA16851E44B}
Adds value: "(default)"
With data: "<Win32/BHO.LI file>"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18CB1A7B-94CD-4582-8022-ADA16851E44B}\InprocServer32
Adds value: "(default)"
With data: "cablerouting.cablerouting.1"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18CB1A7B-94CD-4582-8022-ADA16851E44B}\ProgID
Adds value: "(default)"
With data: "{8b8df25f-2c47-4473-8e1c-7f54ac7ef481}"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18CB1A7B-94CD-4582-8022-ADA16851E44B}\TypeLib
Adds value: "(default)"
With data: "cablerouting.cablerouting"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18CB1A7B-94CD-4582-8022-ADA16851E44B}\VersionIndependentProgID
Adds value: "(default)"
With data: "cablerouting class"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CableRouting.CableRouting
Adds value: "(default)"
With data: "{18cb1a7b-94cd-4582-8022-ada16851e44b}"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CableRouting.CableRouting\CLSID
Adds value: "(default)"
With data: "cablerouting.cablerouting.1"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CableRouting.CableRouting\CurVer
Adds value: "(default)"
With data: "cablerouting class"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CableRouting.CableRouting.1
Adds value: "(default)"
With data: "{18cb1a7b-94cd-4582-8022-ada16851e44b}"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CableRouting.CableRouting.1\CLSID
Adds value: "(default)"
With data: "cablerouting library"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8B8DF25F-2C47-4473-8E1C-7F54AC7EF481}\1.0
Adds value: "(default)"
With data: "<Win32/BHO.LI file>"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8B8DF25F-2C47-4473-8E1C-7F54AC7EF481}\1.0\0\win32
Adds value: "(default)"
With data: "cablerouting module"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18CB1A7B-94CD-4582-8022-ADA16851E44B}
Payload
Connects to Remote Sites
Win32/BHO.LI may connect to various questionable or malicious sites, such as the following:
xiphoman.com
forum.searchengines.ru
bbs.adultwebmasterinfo.com
Blocks Access to Web Sites
Win32/BHO.LI may block access to certain security or antivirus related sites, such as the following:
lecops.com
trojaner-board.de
forum.kaspersky.com
castlecops.com
Downloads and Executes Arbitrary Files
Win32/BHO.LI may download and run other malicious software from a remote Web site. This trojan may also report on the affected user's web browsing to a remote server.
Analysis by Iulian Mihai