Virus: W32/Viking.EM Date discovered: 15/06/2007 Type: File infector In the wild: No Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Low to medium Static file: No File size: 64.063 Bytes IVDF version: 6.39.00.22 - Friday, June 15, 2007
General Methods of propagation: • Infects files • Local network Aliases: • Symantec: W32.Looked.O • Mcafee: W32/HLLP.Philis.ei • Kaspersky: Worm.Win32.Viking.em • Sophos: W32/Looked-EA • VirusBuster: Win32.HLLP.Viking.IZ • Eset: Win32/Viking.CH • Bitdefender: Win32.Worm.Viking.EM Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files • Drops a malicious file • Infects files • Lowers security settings • Registry modification Files It copies itself to the following locations: • %WINDIR% \uninstall\rundl132.exe • %WINDIR% \Logo1_.exe It deletes the initially executed copy of itself. The following files are created: – A file that is for temporary use and it might be deleted afterwards: • %TEMPDIR% \$$a5.tmp – %TEMPDIR% \$$a5.bat Furthermore it gets executed after it was fully created. This batch file is used to delete a file. – %WINDIR% \RichDll.dl Further investigation pointed out that this file is malware, too. Detected as: W32/Viking.EM.dll – %executed file% Furthermore it gets executed after it was fully created. This is the original version of the file before infection. It tries to download some files: – The location is the following: • down.down988.cn/********** – The location is the following: • down.down988.cn/********** – The location is the following: • down.down988.cn/********** – The location is the following: • down.down988.cn/********** – The location is the following: • down.down988.cn/********** – The location is the following: • down.down988.cn/********** – The location is the following: • down.down988.cn/********** – The location is the following: • down.down988.cn/********** – The location is the following: • down.down988.cn/********** – The location is the following: • down.down988.cn/********** Registry The following registry key is added in order to run the process after reboot: – [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] • "load"="%WINDIR% \uninstall\rundl132.exe" The following registry key is added: – [HKLM\Software\Soft\DownloadWWW\] • "auto"="1" File infection Infector type: Prepender - The virus code is added at the begining of the infected file. Stealth: No stealth techinques used. It modifies the OEP (Original Entry Point) of the infected file to point to the virus code. Method: This memory-resistent infector remains active in memory. Infection length: Approximately 64.000 Bytes The following files are infected: By file type: • *.exe Files in any of the following directories: • %all directories% • %network shares% Process termination The following service is disabled: • Kingsoft AntiVirus Service File details Programming language: The malware program was written in Delphi. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • PolyEnE 0.01+
Description inserted by Daniel Constantin on Thursday, February 11, 2010 Description updated by Daniel Constantin on Thursday, February 11, 2010
Back
.
.
.
.