Home Malware Programs Dialers CrossKirk

CrossKirk

Posted: March 28, 2006

CrossKirk is a dialer that connects a compromised PC to the Internet by dialing high-cost phone numbers using a modem. The spyware is designed to provide paid access to pornographic resources. CrossKirk also creates several desktop shortcuts and Start Menu entries. The threat can get into the computer while visiting some insecure adult web sites. It automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ddialer.exe
    2 kernel32.exe
    3 menf[X].exe
    4 od-asia[X].exe
    5 od-stdn[X].exe
    6 od-teen[X].exe
    7 sexgay.gif
    8 st-hc[X].exe
    9 tlk[X].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunlk[X].exeHKEY_CURRENT_USERSoftwareWebdialerHKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionUninstallWebdialer_li-[filename]
Loading...