Virus: TR/Dldr.Small.agq.4 Date discovered: 26/09/2005 Type: Trojan Subtype: Downloader In the wild: Yes Reported Infections: Low Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 4.477 Bytes MD5 checksum: f858bcfec28369d83492a5d406ecf60c VDF version: 6.31.1.64
General Method of propagation: • No own spreading routine Aliases: • Mcafee: BackDoor-AZV • Kaspersky: Trojan-Downloader.Win32.Small.bov • Sophos: Troj/Vixup-Gen • Bitdefender: Trojan.Downloader.Small.AMA Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files Files It copies itself to the following location: • %SYSDIR% \kernels32.exe The following file is created: – Non malicious file: • %SYSDIR% \vx.tll It tries to download some files: – The location is the following: • http://**********/adverts/progs/search.exe It is saved on the local hard drive under: %SYSDIR% \vxh8jkdq1.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: 547 – The location is the following: • http://**********/adverts/progs/winlogon.exe It is saved on the local hard drive under: %SYSDIR% \vxh8jkdq2.exe – The location is the following: • http://**********/adverts/progs/tibs.exe It is saved on the local hard drive under: %SYSDIR% \vxh8jkdq5.exe – The location is the following: • http://**********/adverts/progs/tool.exe It is saved on the local hard drive under: %SYSDIR% \vxh8jkdq6.exe – The location is the following: • http://**********/adverts/progs/proxy.exe It is saved on the local hard drive under: %SYSDIR% \vxh8jkdq7.exe – The location is the following: • http://**********/adverts/progs/search.exe It is saved on the local hard drive under: %SYSDIR% \vxh8jkdq8.exe Registry The following registry key is added in order to run the process after reboot: – [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] • "System" = "%SYSDIR% \kernels32.exe" The following registry key is added: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] • "DisableTaskMgr"=dword:00000001 The following registry key is changed: – [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] Old value: • "Shell" = "Explorer.exe" New value: • "Shell" = "Explorer.exe %SYSDIR% \kernels32.exe" Backdoor Contact server: All of the following: • http://**********/adverts/039/adload.php • http://**********/adverts/039/aduniq.php?vx1=%random character string% As a result it may send some information. This is done via the HTTP GET request on a PHP script. Sends information about: • Current malware status File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • FSG 2.0
Description inserted by Alexandru Tudor on Tuesday, September 27, 2005 Description updated by Alexandru Tudor on Friday, September 30, 2005
Back
.
.
.
.