Virus: TR/Drop.Agent.avam Date discovered: 26/10/2009 Type: Trojan Subtype: Dropper In the wild: Yes Reported Infections: Medium Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 745.472 Bytes MD5 checksum: 0C59eadc2628f66819ee0F76f5eeb910 IVDF version: 7.01.04.220 - Saturday, July 11, 2009
General Method of propagation: • No own spreading routine Aliases: • Kaspersky: Trojan.Win32.Obfuscated.whl • Sophos: W32/IRCBot-ADJ • Panda: Bck/Mircbased.BT • Eset: IRC/Cloner.BX trojan • Bitdefender: Trojan.AgentMB.ITGL3168337 Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Disable security applications • Drops files • Drops malicious files • Lowers security settings • Registry modification • Third party control Files It copies itself to the following locations: • %PROGRAM FILES% \Microsoft Office\OFFICE11\ WINWORD.EXE • %PROGRAM FILES% \Microsoft Office\OFFICE11\services.exe • %Start Menu%\Programs\Startup\Adobe Gamma Loader.com It creates the following directory: • %PROGRAM FILES% \Microsoft Office\OFFICE11 The following files are created: – %PROGRAM FILES% \Microsoft Office\OFFICE11\Drvics32.dll Contains parameters used by the malware. – %PROGRAM FILES% \Microsoft Office\OFFICE11\hjwgsd.dll Contains parameters used by the malware. – %PROGRAM FILES% \Microsoft Office\OFFICE11\jwiegh.dll Contains parameters used by the malware. – %PROGRAM FILES% \Microsoft Office\OFFICE11\remote.ini Contains parameters used by the malware. – %PROGRAM FILES% \Microsoft Office\OFFICE11\ruimsbbe.dll Contains parameters used by the malware. – %PROGRAM FILES% \Microsoft Office\OFFICE11\control.ini Contains parameters used by the malware. – %PROGRAM FILES% \Microsoft Office\OFFICE11\PUB60SP.mrc Further investigation pointed out that this file is malware, too. Detected as: WORM/IrcBot.7385.A – %PROGRAM FILES% \Microsoft Office\OFFICE11\yofc.dll Further investigation pointed out that this file is malware, too. Detected as: IRC/Zapchast.YF – %PROGRAM FILES% \Microsoft Office\OFFICE11\smss.exe Further investigation pointed out that this file is malware, too. Detected as: TR/Spy.576628.2 Registry The following registry key is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] • "Shell"="Explorer.exe, %PROGRAM FILES% \Microsoft Office\OFFICE11\services.exe" The values of the following registry key are removed: – [HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings] • "ProxyServer" • "ProxyOverride" • "AutoConfigURL" – [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ %all registry keys%] – [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ %all registry keys%] The following registry keys are added: – [HKCR\exefile] • "NeverShowExt"="" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\Acha.exe] • "Debugger"="cmd.exe /c del" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\registry.exe] • "Debugger"="cmd.exe /c del" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\AmyMastura.exe] • "Debugger"="cmd.exe /c del" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\csrsz.exe] • "Debugger"="cmd.exe /c del" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\SMSSS.exe] • "Debugger"="cmd.exe /c del" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\lsasc.exe] • "Debugger"="cmd.exe /c del" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\BabyRina.exe] • "Debugger"="cmd.exe /c del" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\wscript.exe] • "Debugger"="rundll32.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\cscript.exe] • "Debugger"="rundll32.exe" – [HKLM\SOFTWARE\Microsoft\Security Center\Svc] • "AntiVirusDisableNotify"=dword:00000001 • "AntiVirusOverride"=dword:00000001 • "FirewallDisableNotify"=dword:00000001 • "FirewallOverride"=dword:00000001 • "FirstRunDisabled"=dword:00000001 • "UpdatesDisableNotify"=dword:00000001 • "UacDisableNotify"=dword:00000001 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] • "EnableLUA"=dword:00000000 The following registry keys are changed: Various Explorer settings: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] New value: • "ShowSuperHidden"="0x0" • "SuperHidden"="0x0" Various Explorer settings: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ Folder\SuperHidden] New value: • "CheckedValue"=dword:00000000 • "UncheckedValue"=dword:00000000 • "DefaultValue"=dword:00000000 – [HKLM\SOFTWARE\Microsoft\Security Center] New value: • "AntiVirusDisableNotify"=dword:00000001 • "FirewallDisableNotify"=dword:00000001 • "UpdatesDisableNotify"=dword:00000001 • "AntiVirusOverride"=dword:00000001 • "FirewallOverride"=dword:00000001 • "FirstRunDisabled"=dword:00000001 • "UacDisableNotify"=dword:00000001 – [HKLM\SYSTEM\CurrentControlSet\Services\wuauserv] New value: • "Type"=dword:00000004 • "Start"=dword:00000004 – [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess] New value: • "Type"=dword:00000004 • "Start"=dword:00000004 – [HKLM\SYSTEM\CurrentControlSet\Services\WinDefend] New value: • "Type"=dword:00000004 • "Start"=dword:00000004 IRC To deliver system information and to provide remote control it connects to the following IRC Server: Server: irc.dal.net Port: 6667 Nickname: Gold_girXls Miscellaneous Checks for an internet connection by contacting the following web sites: • www.tourism.gov.my • www.miti.gov.my • www.putera.com Rootkit Technology Hides the following: – Its own files File details Programming language: The malware program was written in Visual Basic.
Description inserted by Raluca Georgescu on Monday, October 26, 2009 Description updated by Andrei Ivanes on Tuesday, October 27, 2009
Back
.
.
.
.