Interpretation of SavedLegacySettings



We are investigating malware that changes the
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Connections\SavedLegacySettings value. The value is altered,
but we see no change in Control Panel | Internet Options | Connections
(tab) | Settings...

Several malware species that change this value have been reported:
W32.MyDoom.AB: http://tinyurl.com/47fv8
VP Killer trojan: http://tinyurl.com/82frk

We've looked at the Microsoft documentation about SavedLegacySettings
( http://tinyurl.com/b3po9) but it's paltry explanation.

What does this value do exactly? Why does malware change it? How can
the binary value be interpreted? Can the value be changed via the GUI?
If so, how? If not, why not?

regards, Andy
--
**********

Please send e-mail to: usenet (dot) post (at) aaronoff (dot) com

To identify everything that starts up with Windows, download
"Silent Runners.vbs" at www.silentrunners.org

**********
.



Relevant Pages

  • Re: Error messages an slow computer
    ... Is McAfee malware Ken? ... Enquire, plan and execute ... all the connections and they seem to be fine. ... I've done a disk cleanup and a disk defragment. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Internet Options does not start!
    ... cannot access it via Control Panel either..... ... Try accessing Internet Options in Safe Mode. ... you probably have malware. ... want to open Internet Options? ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Third Party Browser Extensions
    ... Tools, internet options, settings button, view objects. ... Make sure malware is not interfering. ... AdAware is now version 6.181. ... An experienced computer technician can use programme such as AutoStart ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Third Party Browser Extensions
    ... Tools, internet options, settings button, view objects. ... Make sure malware is not interfering. ... AdAware is now version 6.181. ... An experienced computer technician can use programme such as AutoStart ...
    (microsoft.public.windows.inetexplorer.ie6.setup)
  • RE: Desktop
    ... that web-site, which always appear when you log on. ... Go through the general malware removal steps - including all preparatory ... Here is some additional information about getting rid of the background ... Go to the Display applet in Control Panel and look on the Desktop tab. ...
    (microsoft.public.windowsxp.general)