Date discovered:05/03/2010
In the wild:Yes
Reported Infections:Low to medium
Distribution Potential:Medium
Damage Potential:Low to medium
Static file:Yes
File size:192.512 Bytes
MD5 checksum:b91cf5a837c1f7fe459bd5cdfe079dcf
IVDF version:

 General Methods of propagation:
   • Autorun feature
   • Messenger
   • Peer to Peer

   •  Mcafee: Generic.dx
   •  Sophos: Mal/VBInject-D
   •  Panda: W32/MSNWorm.HV
   •  Eset: Win32/Peerfrag.FL
   •  Bitdefender: Worm.Generic.232328

Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003

Side effects:
   • Downloads malicious files
   • Drops malicious files
   • Registry modification

 Files It copies itself to the following locations:
   • %recycle bin%\%CLSID%\yv8g67.exe
   • %drive%\Docs\print.exe

The following files are created:

– %recycle bin%\%CLSID%\Desktop.ini
%drive%\autorun.inf This is a non malicious text file with the following content:
   • %code that runs malware%

It tries to download some files:

 Registry The following registry key is added in order to run the process after reboot:

– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   • "Taskman"="%recycle bin%\%CLSID%\yv8g67.exe"

 P2P In order to infect other systems in the Peer to Peer network community the following action is performed:   It retrieves shared folders by querying the following registry keys:
   • Software\BearShare\General
   • Software\iMesh\General
   • Software\Shareaza\Shareaza\Downloads
   • Software\Kazaa\LocalContent
   • Software\DC++
   • Software\eMule
   • Software\Microsoft\Windows\CurrentVersion\Uninstall\eMule Plus_is1

   It searches for directories that contain the following substring:
   • \Local Settings\Application Data\Ares\My Shared Folder

 Messenger It is spreading via Messenger. The characteristics are described below:

– MSN Messenger

The URL then refers to a copy of the described malware. If the user downloads and executes this file the infection process will start again.

 Backdoor The following ports are opened:

– f5v**********.com on UDP port 443
– f5v**********.com on UDP port 5190

 Injection – It injects itself as a remote thread into a process.

    Process name:
   • explorer.exe

 File details Programming language:
The malware program was written in Visual Basic.

Die Beschreibung wurde erstellt von Petre Galan am Freitag, 2. Juli 2010
Die Beschreibung wurde geändert von Petre Galan am Freitag, 2. Juli 2010

