Virus:TR/Autoit.2043904
Date discovered:22/09/2009
Type:Trojan
In the wild:Yes
Reported Infections:Low to medium
Distribution Potential:Low to medium
Damage Potential:Medium
Static file:Yes
File size:2.043.904 Bytes
MD5 checksum:ca6faa700e997677dd903570b3f8624a
IVDF version:7.01.06.24 - Tuesday, September 22, 2009

 General Method of propagation:
• Autorun feature


Aliases:
   •  Mcafee: W32/Autorun.worm.bz virus
   •  Sophos: W32/AutoIt-EQ
   •  Panda: W32/Sohanat.HR.worm
   •  Eset: Win32/AutoRun.Autoit.P
   •  Bitdefender: Worm.Autoit.B


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003


Side effects:
   • Drops malicious files
   • Registry modification

 Files It copies itself to the following locations:
   • %WINDIR%\MsRun32.exe
   • %SYSDIR%\MsRun32.exe
   • %drive%\True_Love.exe
   • %drive%\MsRun32.exe
   • %drive%\%randomly chosen directory%\%directory name%.exe



The following files are created:

%SYSDIR%\autorun.ini
%drive%\autorun.inf This is a non malicious text file with the following content:
   • %code that runs malware%

%drive%\%all directories%\%directory name% .exe Further investigation pointed out that this file is malware, too. Detected as: Worm/AutoIt.X

%drive%\%randomly chosen directory%\%directory name%.exe Detected as: Worm/Autorun.K

 Registry One of the following values is added in order to run the process after reboot:

–  [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "MSN Messengger"="%SYSDIR%\MsRun32.exe"



The following registry keys are added:

– [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
   • "DisableRegistryTools"=dword:0x00000001
   • "DisableTaskMgr"=dword:0x00000001

– [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
   WorkgroupCrawler\Shares]
   • "shared"="\True_Love.exe"



The following registry keys are changed:

– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   New value:
   • "Shell"="Explorer.exe MsRun32.exe"

– [HKCU\Software\Microsoft\Windows NT\CurrentVersion\TaskManager]
   New value:
   • "Preferences"=hex:9C,02,00,00,E8,03,00,00,02,00,00,00,01,00,00,00,01,00,00,00,5A,02,00,00,02,00,00,00,FA,04,00,00,18,03,00,00,01,00,00,00,00,00,00,00,02,00,00,00,03,00,00,00,04,00,00,00,FF,FF,FF,FF,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,00,00,00,00,00,00,01,00,00,00,02,00,00,00,03,00,00,00,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,01,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,02,00,00,00,04,00,00,00,06,00,00,00,0B,00,00,00,0E,00,00,00,FF,FF,FF,FF,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,6B,00,00,00,32,00,00,00,6B,00,00,00,23,00,00,00,46,00,00,00,46,00,00,00,3C,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,00,00,00,00,01,00,00,00,02,00,00,00,03,00,00,00,04,00,00,00,05,00,00,00,06,00,00,00,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,6F,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00

– [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
   New value:
   • "NofolderOptions"=dword:0x00000001

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
   Folder\Hidden\SHOWALL]
   New value:
   • "CheckedValue"=dword:0x00000000

 Process termination The following process is terminated:
   • taskmgr.exe


 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Description inserted by Petre Galan on Thursday, December 10, 2009
Description updated by Petre Galan on Thursday, December 10, 2009

Back . . . .