Virus: Worm/Sohaned.BP Date discovered: 07/11/2008 Type: Worm In the wild: Yes Reported Infections: Low Distribution Potential: Low to medium Damage Potential: Low to medium Static file: Yes File size: 327.109 Bytes MD5 checksum: 8c4c10bc0cd60742a57eb6a4e6f3c261 IVDF version: 7.01.00.55 - Friday, November 7, 2008
General Method of propagation: • Autorun feature Aliases: • Mcafee: W32/YahLover.worm.gen • Panda: W32/Autorun.JHJ • Eset: Win32/Autoit.EB • Bitdefender: Worm.Generic.39680 Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files • Drops malicious files • Registry modification Files It copies itself to the following locations: • %SYSDIR% \gphone.exe • %WINDIR% \gphone.exe • %drive% \gphone.exe The following files are created: – %drive% \autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %SYSDIR% \autorun.ini Further investigation pointed out that this file is malware, too. Detected as: Worm/AutoIt.AV It tries to download some files: – The location is the following: • http://rnd009.googlepages.com/********** At the time of writing this file was not online for further investigation. – The location is the following: • http://rnd009.googlepages.com/********** At the time of writing this file was not online for further investigation. Registry One of the following values is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "Yahoo Messengger"="%SYSDIR% \gphone.exe" The following registry key is added: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] • "DisableRegistryTools"=dword:0x00000001 • "DisableTaskMgr"=dword:0x00000001 The following registry keys are changed: – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] New value: • "Shell"="Explorer.exe gphone.exe" – [HKLM\SYSTEM\CurrentControlSet\Services\Schedule] New value: • "AtTaskMaxHours"=dword:0x00000000 – [HKCU\Software\Microsoft\Internet Explorer\Main] New value: • "Start Page"="http://rnd009.googlepages.com/google.html" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] New value: • "NofolderOptions"=dword:0x00000001 – [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main] New value: • "Default_Page_URL"="http://rnd009.googlepages.com/google.html" • "Default_Search_URL"="http://rnd009.googlepages.com/google.html" • "Search Page"="http://rnd009.googlepages.com/google.html" • "Start Page"="http://rnd009.googlepages.com/google.html" File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Thursday, March 11, 2010 Description updated by Petre Galan on Thursday, March 11, 2010
Back
.
.
.
.