InstantAccess
InstantAccess Description
InstantAccess is a porn dialer which, by exploiting the user’s modem, connects to pornographic servers. InstantAccess automatically launches on every startup and reboot. This will result in the user’s phone line being charged high rates. Additional malware may also be installed by InstantAccess.
Type: Dialers
Automatic Detection of InstantAccess
InstantAccess has typically the following processes in memory:
- nethv32.dll
- Mservice.dll
- eglivecam_1028.dll
- eglivecam_1028.dll
- Mservice.dll
- EGAUTH.dll
- mseggrpid.dll
- p2esocks_1020.dll
- eglivecam_1028.dll
- mseggrpid.dll
- EGAUTH.dll
- EGAUTH.dll
- mseggrpid.dll
- p2esocks_1020.dll
- msegcompid.dll
- nethv32.dll
- EGAUTH.dll
- msegcompid.dll
- p2esocks_1020.dll
- nethv32.dll
- msegcompid.dll
- nethv32.dll
- eglivecam_1028.dll
- Mservice.dll
InstantAccess creates the following registry entries:
- SOFTWAREMicrosoftWindowsCurrentVersionModuleUsageC:/WINDOWS/System32/EGAUTH.dll
- SOFTWARE\Microsoft\Code Store Database\Distribution Units\0594AF7E-573B-40DF-8165-E47AB2EAEFE8
- SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/eglivecam_1028.dll
- MService
- 43CDAD65-AA0D-4701-8108-117F86613B69
- 0E594D22-ACE6-43A2-BCDA-BB7C65D3FE8C
- EGAUTH.EGEGAUTH
- MagicControl.MagicComponent.1
- 469C7080-8EC8-43A6-AD97-45848113743C
- SOFTWAREMicrosoftWindowsCurrentVersionModuleUsageC:/WINDOWS/System32/nethv32.dll
- SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/EGAUTH.dll
- EGDHTML
- 3947AC1D-DB09-4353-BBCC-55B97F5035EF
- A58F3D09-4543-4396-8BE7-105F14DD6ED5
- 82C0673C-F1D1-47BA-B904-AB0DE82300BC
- MagicControl.MagicComponent
- 469C7080-8EC8-43A6-AD97-45848113743C
- 0594AF7E-573B-40DF-8165-E47AB2EAEFE8
- SOFTWAREMicrosoftWindowsCurrentVersionModuleUsageC:/WINDOWS/System32/eglivecam_1028.dll
- SOFTWARE\Microsoft\Code Store Database\Distribution Units\469C7080-8EC8-43A6-AD97-45848113743C
- SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/nethv32.dll
- P2EClient
- 510C3373-4842-4944-8729-0AFF6725A132
- 7ACD434E-3DBB-415F-9D04-0C4ED32DE403
- EGAUTH.EGEGAUTH.1
- 0594AF7E-573B-40DF-8165-E47AB2EAEFE8
Important Article Disclaimer

This entry was posted
on 09/14/08 and is filed under Dialers.
You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.

English 

InstantAccess 










