Threat Database Trojans JS.Proslikefan

JS.Proslikefan

By Domesticus in Trojans

Threat Scorecard

Ranking: 3,495
Threat Level: 20 % (Normal)
Infected Computers: 5,878
First Seen: September 14, 2012
Last Seen: September 19, 2023
OS(es) Affected: Windows

JS.Proslikefan is a JavaScript worm that proliefrates through file-sharing programs, removable drives and mapped network shares. While being executed, JS.Proslikefan may replicate itself to the particular locations. JS.Proslikefan can make modifications to several files in order to change the computer user's home page. JS.Proslikefan may contact the command-and-control (C&C) server. JS.Proslikefan collects information from the affected computer including installed anti-virus software information, computer name, OS version, user name, script information and sends it to the C&C server. If the Internet user is logged in to Facebook, JS.Proslikefan may perform the certain actions, such as setup a chat, Like a page, or become a fan of a page. JS.Proslikefan modifies the hosts file in order to blockt access to numerous security-related domains.

File System Details

JS.Proslikefan may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\uc\cu.js
2. %DriveLetter%\autorun.inf
3. %ProgramFiles%\3db7\3cb3.js
4. %UserProfile%\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
5. %DriveLetter%\[SCRIPT NAME].js
6. %UserProfile%\Start Menu\Programs\Startup\[ENCODED STRING].js
7. %UserProfile%\Local Settings\Application Data\Mozilla\Firefox\Profiles\user.js
8. %SystemDrive%\prospect\knock

Registry Details

JS.Proslikefan may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjects\{FD6905CE-952F-41F1-9A6F-135D9C6622CC}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"ProxyEnable" = "0"
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\"DisableCMD" = "1"
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\"HomePage" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\"UpdatesDisableNotify" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoControlPanel" = "1"
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\"DisableTaskMgr" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"Hidden" = "2"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\"SystemRestoreDisableSR" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\"Start Page"22 = "[VALUE FROM CONFIGURATION FILE]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix\"Default" = "[VALUE FROM CONFIGURATION FILE]"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\"ParseAutoexec" = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\"AntiVirusDisableNotify" = "1"
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\"NoDispCPL" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoWindowsUpdate" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\"DisableConfig" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\"AntiVirusOverride" = "1"
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\"DisableRegistryTools" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"HideFileExt" = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\"www" = "[VALUE FROM CONFIGURATION FILE]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"cu" = "%UserProfile%\Application Data\uc\cu.js"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"MigrateProxy" = "0"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\"EnableFirewall" = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\"FirewallDisableNotify" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NofolderOptions" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\"HomePage" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MRT\"DontReportInfectionInformation" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\"FirewallOverride" = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\"Start" = "4"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Start Page" = "[VALUE FROM CONFIGURATION FILE]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\"Default" = "[VALUE FROM CONFIGURATION FILE]"

URLs

JS.Proslikefan may call the following URLs:

thenewstreams.com

Trending

Most Viewed

Loading...