Virus:Worm/VB.bdy
Date discovered:27/03/2007
Type:Worm
In the wild:Yes
Reported Infections:Low
Distribution Potential:Low to medium
Damage Potential:Low
Static file:Yes
File size:40.960 Bytes
MD5 checksum:d759464539422a77a9fb5bf0ac3a77c1
VDF version:6.38.00.117
IVDF version:6.38.00.120 - Tuesday, March 27, 2007

 General Method of propagation:
   • Mapped network drives


Aliases:
   •  Kaspersky: Virus.Win32.VB.dg
   •  F-Secure: Virus.Win32.VB.dg
   •  Grisoft: Worm/VB.AWV


Platforms / OS:
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


Right after execution the following information is displayed:


 Files It copies itself to the following locations:
   • %HOME%\START MENU\PROGRAMS\STARTUP\Adobe Online.com
   • %HOME%\START MENU\PROGRAMS\STARTUP\Adobe update.com
   • %current directory%\%all subdirectories%.scr



It copies the following files:
    •  %malware execution directory%\Thumbs .db into %WINDIR%\Thumbs .db
    •  %malware execution directory%\Thumbs .db into c:\Thumbs .db



The following file is created:

– c:\Autorun.inf This is a non malicious text file with the following content:
   • [Autorun]
     Open=Thumbs.com -a
     ShellExecute=Thumbs.com
     Shell\Auto\Command=Thumbs.com
     Shell=Auto
     
     [Definitions]
     Launchpad=Thumbs.com
     Vtype=1

 Registry The following registry key is added:

– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   • "LegalNoticeCaption"="81u3f4nt45y - 24.01.2007 - Surabaya"
   • "LegalNoticeText"="Surabaya in my birthday
   • Don't kill me, i'm just send message from your computer
   • Terima kasih telah menemaniku walaupun hanya sesaat, tapi bagiku sangat berarti
   • Maafkan jika kebahagiaan yang kuminta adalah teman sepanjang hidupku
   • Seharusnya aku mengerti bahwa keberadaanku bukanlah disisimu, hanyalah lamunan dalam sesal
   • Untuk kekasih yang tak kan pernah kumiliki 3r1k1m0"



The following registry keys are changed:

– [HKCR\scrfile]
   New value:
   • @="File Folder"
     "InfoTip"=""
     "NeverShowExt"=""
     "TileInfo"=""

– [HKCR\scrfile\shell\config\command]
   New value:
   • @="\"%1\""

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
   Folder\Hidden\NOHIDDEN]
   New value:
   • "CheckedValue"=dword:00000002
     "DefaultValue"=dword:00000002

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
   Folder\Hidden\SHOWALL]
   New value:
   • "CheckedValue"=dword:00000000
     "DefaultValue"=dword:00000002

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
   Folder\HideFileExt]
   New value:
   • "CheckedValue"=dword:00000001
     "DefaultValue"=dword:00000001
     "UncheckedValue"=dword:00000001

 File details Programming language:
The malware program was written in Visual Basic.

Description inserted by Gabriel Mustata on Monday, March 26, 2007
Description updated by Gabriel Mustata on Tuesday, March 27, 2007

Back . . . .