Virus: TR/Click.Small.HR Date discovered: 23/08/2005 Type: Trojan In the wild: No Reported Infections: Low Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 20.480 Bytes MD5 checksum: aab0b0d92b441763d45cff47c9224bcb VDF version: 6.31.1.140
General Method of propagation: • No own spreading routine Aliases: • Symantec: PWSteal.Lemir • Kaspersky: Trojan-Clicker.Win32.Small.hr • Panda: Trj/Agent.AIA • Bitdefender: Trojan.Clicker.Small.HR Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows 2000 • Windows XP Side effects: • Disable security applications • Registry modification Files It copies itself to the following location: • %SYSDIR% \iexplore.exe It deletes the initially executed copy of itself. The following file is created: – %WINDIR% \deleteme.bat Furthermore it gets executed after it was fully created. This batch file is used to delete a file. Registry The following registry key is added in order to run the process after reboot: – HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run • "Microsoft"="%SYSDIR% \iexplore.exe" The values of the following registry keys are removed: – HKLM\SoftWare\Microsoft\Windows\CurrentVersion\Run • RavMon • KAVPersonal50 • RavTimer • KvMonXP • iDuba Personal FireWall • KAVRun • KpopMon • Kulansyn • KavPFW • KvXP • ccApp • SSC_UserPrompt • NAV CfgWiz • MCAgentExe • McRegWiz • MCUpdateExe • MSKAGENTEXE • MSKDetectorExe • VirusScan Online • VSOCheckTask • McAfeeUpdaterUI • Network Associates Error Reporting Service • ShStatEXE • KavStart • Services • KWatch9x – HKCU\SoftWare\Microsoft\Windows\CurrentVersion\Run • iDuba Personal FireWall • KavPFW • KvXP The following registry keys are added: – HKLM\SYSTEM\CurrentControlSet\Services\RsRavMon • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\RsCCenter • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\kavsvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\KVSrvXP • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\wscsvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\ccProxy • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\ccEvtMgr • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\ccSetMgr • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\SPBBCSvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\Symantec Core LC • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\navapsvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\NPFMntor • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\MskService • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\FireSvc • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\McShield • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\McTaskManager • Start=dword:00000004 – HKLM\SYSTEM\CurrentControlSet\Services\McAfeeFramework • Start=dword:00000004 Process termination List of processes that are terminated: • CCAPP.EXE; EGHOST.EXE; explor.exe; FireTray.exe; Iparmor.exe; KATMain.EX; KAV32.EXE; KAVPFW.EXE; KAVPLUS.EXE; KAVStart.exe; KmailMon.EXE; KPOPMON.EXE; KRegEx.exe; KVCENTER.KXP; KvDetech.exe; KVFW.EXE; KVMonXP.KXP; KVOL.exe; kvolself.exe; KVXP.KXP; KWatch9x.exe; KWATCHUI.EXE; MAILMON.EXE; MCAGENT.EXE; MCVSESCN.EXE; MSKAGENT.EXE; RAV.EXE; RAVMON.EXE; RAVTIMER.EXE; SHSTAT.EXE; SOFTOK.EXE; TBMon.exe; TrojanDetector.EXE; TrojDie.kxp; UpdaterUI.exe; windox.exe Processes with the following characteristics are terminated: • Title: Symantec AntiVirus Class name: KV2004 • Title: RavMon.exe Class name: RavMonClass • Title: ZoneAlarm Class name: ZAFrameWnd • Title: %double-byte-characters% Class name: Tapplication • Title: %double-byte-characters% Class name: TForm1 • Title: %random% Class name: TfLockDownMain • Title: %random% Class name: KvXP_ExpertFrame • Title: %random% Class name: WHXMDI0 List of services that are disabled: • ccEvtMgr; ccProxy; ccSetMgr; FireSvc; kavsvc; KPfwSvc; KVSrvXP; KWatchSvc; McAfeeFramework; McShield; McTaskManager; MskService; navapsvc; NPFMntor; RsCCenter; RsRavMon; SNDSrvc; SPBBCSvc; Symantec Core LC; wscsvc File details Programming language: The malware program was written in Delphi. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • UPX
Description inserted by Irina Boldea on Tuesday, August 23, 2005 Description updated by Irina Boldea on Monday, August 29, 2005
Back
.
.
.
.