InstantAccess
InstantAccess Description
InstantAccess is a porn dialer which, by exploiting the user’s modem, connects to pornographic servers. InstantAccess automatically launches on every startup and reboot. This will result in the user’s phone line being charged high rates. Additional malware may also be installed by InstantAccess.
Type: Dialers
How Can You Detect InstantAccess?
InstantAccess has typically the following processes in memory:
- nethv32.dll
- Mservice.dll
- eglivecam_1028.dll
- eglivecam_1028.dll
- Mservice.dll
- EGAUTH.dll
- mseggrpid.dll
- p2esocks_1020.dll
- eglivecam_1028.dll
- mseggrpid.dll
- EGAUTH.dll
- EGAUTH.dll
- mseggrpid.dll
- p2esocks_1020.dll
- msegcompid.dll
- nethv32.dll
- EGAUTH.dll
- msegcompid.dll
- p2esocks_1020.dll
- nethv32.dll
- msegcompid.dll
- nethv32.dll
- eglivecam_1028.dll
- Mservice.dll
InstantAccess creates the following registry entries:
- SOFTWAREMicrosoftWindowsCurrentVersionModuleUsageC:/WINDOWS/System32/EGAUTH.dll
- SOFTWARE\Microsoft\Code Store Database\Distribution Units\0594AF7E-573B-40DF-8165-E47AB2EAEFE8
- SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/eglivecam_1028.dll
- MService
- 43CDAD65-AA0D-4701-8108-117F86613B69
- 0E594D22-ACE6-43A2-BCDA-BB7C65D3FE8C
- EGAUTH.EGEGAUTH
- MagicControl.MagicComponent.1
- 469C7080-8EC8-43A6-AD97-45848113743C
- SOFTWAREMicrosoftWindowsCurrentVersionModuleUsageC:/WINDOWS/System32/nethv32.dll
- SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/EGAUTH.dll
- EGDHTML
- 3947AC1D-DB09-4353-BBCC-55B97F5035EF
- A58F3D09-4543-4396-8BE7-105F14DD6ED5
- 82C0673C-F1D1-47BA-B904-AB0DE82300BC
- MagicControl.MagicComponent
- 469C7080-8EC8-43A6-AD97-45848113743C
- 0594AF7E-573B-40DF-8165-E47AB2EAEFE8
- SOFTWAREMicrosoftWindowsCurrentVersionModuleUsageC:/WINDOWS/System32/eglivecam_1028.dll
- SOFTWARE\Microsoft\Code Store Database\Distribution Units\469C7080-8EC8-43A6-AD97-45848113743C
- SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/nethv32.dll
- P2EClient
- 510C3373-4842-4944-8729-0AFF6725A132
- 7ACD434E-3DBB-415F-9D04-0C4ED32DE403
- EGAUTH.EGEGAUTH.1
- 0594AF7E-573B-40DF-8165-E47AB2EAEFE8
Important Article Disclaimer
This entry was posted on 09/14/08 and is filed under Dialers.
You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

English 
Deutsch
Español
Français
Portuguese
InstantAccess 











