Virus: TR/Autoit.2043904 Date discovered: 22/09/2009 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Medium Static file: Yes File size: 2.043.904 Bytes MD5 checksum: ca6faa700e997677dd903570b3f8624a IVDF version: 7.01.06.24 - Tuesday, September 22, 2009
General Method of propagation: • Autorun feature Aliases: • Mcafee: W32/Autorun.worm.bz virus • Sophos: W32/AutoIt-EQ • Panda: W32/Sohanat.HR.worm • Eset: Win32/AutoRun.Autoit.P • Bitdefender: Worm.Autoit.B Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Drops malicious files • Registry modification Files It copies itself to the following locations: • %WINDIR% \MsRun32.exe • %SYSDIR% \MsRun32.exe • %drive% \True_Love.exe • %drive% \MsRun32.exe • %drive% \%randomly chosen directory% \%directory name%.exe The following files are created: – %SYSDIR% \autorun.ini – %drive% \autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %drive% \%all directories% \%directory name% .exe Further investigation pointed out that this file is malware, too. Detected as: Worm/AutoIt.X – %drive% \%randomly chosen directory% \%directory name%.exe Detected as: Worm/Autorun.K Registry One of the following values is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "MSN Messengger"="%SYSDIR% \MsRun32.exe" The following registry keys are added: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] • "DisableRegistryTools"=dword:0x00000001 • "DisableTaskMgr"=dword:0x00000001 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ WorkgroupCrawler\Shares] • "shared"="\True_Love.exe" The following registry keys are changed: – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] New value: • "Shell"="Explorer.exe MsRun32.exe" – [HKCU\Software\Microsoft\Windows NT\CurrentVersion\TaskManager] New value: • "Preferences"=hex:9C,02,00,00,E8,03,00,00,02,00,00,00,01,00,00,00,01,00,00,00,5A,02,00,00,02,00,00,00,FA,04,00,00,18,03,00,00,01,00,00,00,00,00,00,00,02,00,00,00,03,00,00,00,04,00,00,00,FF,FF,FF,FF,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,00,00,00,00,00,00,01,00,00,00,02,00,00,00,03,00,00,00,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,01,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,02,00,00,00,04,00,00,00,06,00,00,00,0B,00,00,00,0E,00,00,00,FF,FF,FF,FF,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,6B,00,00,00,32,00,00,00,6B,00,00,00,23,00,00,00,46,00,00,00,46,00,00,00,3C,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,00,00,00,00,01,00,00,00,02,00,00,00,03,00,00,00,04,00,00,00,05,00,00,00,06,00,00,00,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,6F,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] New value: • "NofolderOptions"=dword:0x00000001 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ Folder\Hidden\SHOWALL] New value: • "CheckedValue"=dword:0x00000000 Process termination The following process is terminated: • taskmgr.exe File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Thursday, December 10, 2009 Description updated by Petre Galan on Thursday, December 10, 2009
Back
.
.
.
.