Virus: TR/Dldr.Harnig.BD.1 Date discovered: 10/04/2006 Type: Trojan Subtype: Downloader In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 5.637 Bytes MD5 checksum: 9aa32c86cd9a164e4bf1b3eebf187c73 VDF version: 6.34.00.165
General Method of propagation: • No own spreading routine Aliases: • Kaspersky: Trojan-Downloader.Win32.Harnig.bd • TrendMicro: TROJ_DLOADER.COH • Bitdefender: Trojan.Downloader.Small.YU Platforms / OS: • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads files • Downloads malicious files • Lowers security settings Files It tries to download some files: – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\uniq – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\kl1.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/PSW.Sinowal.H – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\tool2.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: ADSPY/Hoax.Renos.AG – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\country.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Killav.DB.2 – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: %PROGRAM FILES% \secure32.html – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: %PROGRAM FILES% \paytime.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/StartPage.adi.7 – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\toolbar.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Killav.DB.2 – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\tool1.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Proxy.Small.BO.Dldr – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\tool3.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Dldr.Tiny.AP.3 – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\tool4.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Proxy.Small.BO.18 – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\tool5.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Click.Small.KR – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\ms1.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Dldr.S.CJG.325.D – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: %WINDIR% \Hosts – The location is the following: • http://traffdollars.biz/progs_exe/kjazw/********** It is saved on the local hard drive under: c:\uniq Registry The following registry key including all values and subkeys is removed: • [HKLM\CurrentControlSet\Services\SharedAccess] Process termination The following service is disabled: • Windows Firewall/Internet Connection Sharing (ICS) File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • FSG
Description inserted by Andrei Ivanes on Wednesday, April 12, 2006 Description updated by Andrei Gherman on Thursday, April 13, 2006
Back
.
.
.
.