Virus: TR/Buzus.cptr Date discovered: 23/11/2009 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Medium Static file: Yes File size: 262.144 Bytes MD5 checksum: 20f60d32f26b0bcc1b17aa994ddeed14 IVDF version: 7.10.01.47 - Monday, November 23, 2009
General Method of propagation: • Autorun feature Aliases: • Mcafee: W32/Palack.worm • Sophos: W32/AutoRun-AVL • Panda: W32/P2PWorm.EK.worm • Eset: Win32/AutoRun.IRCBot.DI • Bitdefender: Trojan.Dropper.VB Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Drops malicious files • Registry modification • Third party control Files It copies itself to the following locations: • %SYSDIR% \wmispm.exe • %drive% \RECDIR-5902\data.sys It deletes the initially executed copy of itself. It deletes the following file: • %TEMPDIR% \melt.bat The following files are created: – %drive% \autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %TEMPDIR% \melt.bat Furthermore it gets executed after it was fully created. This batch file is used to delete a file. It tries to executes the following files: – Filename: • net stop avg8wd – Filename: • "%SYSDIR% \wmispm.exe" – Filename: • net1 stop AntiVirService – Filename: • CMD /C sc stop SbPF.Launcher – Filename: • sc stop avg8wd – Filename: • CMD /C sc config "avast! Antivirus" start= disabled – Filename: • sc stop NOD32krn – Filename: • CMD /C sc config AntiVirService start= disabled – Filenames: • "C:\WORK\!ITW • 44.exe" – Filename: • CMD /C sc config avg8wd start= disabled – Filename: • cmd /c ""%TEMPDIR% \melt.bat" " – Filename: • sc config avg8wd start= disabled – Filename: • CMD /C sc delete "avast! Antivirus" – Filename: • CMD /C sc stop "avast! Antivirus" – Filename: • sc delete AntiVirService – Filename: • CMD /C del /F /S /Q *.zip – Filename: • CMD /C sc delete PASRV – Filename: • sc stop SbPF.Launcher – Filename: • CMD /C sc stop avg8wd – Filename: • CMD /C sc stop AntiVirService – Filename: • net1 stop VSSERV – Filename: • CMD /C net stop VSSERV – Filename: • net stop SbPF.Launcher – Filename: • CMD /C del /F /S /Q *.scr – Filename: • sc config SbPF.Launcher start= disabled – Filename: • sc delete SbPF.Launcher – Filename: • CMD /C sc delete VSSERV – Filename: • net stop NOD32krn – Filename: • sc delete PASRV – Filename: • net stop AntiVirService – Filename: • sc delete VSSERV – Filename: • CMD /C net stop SbPF.Launcher – Filename: • sc config "avast! Antivirus" start= disabled – Filename: • net1 stop "avast! Antivirus" – Filename: • sc config AntiVirService start= disabled – Filename: • CMD /C del /F /S /Q *.com – Filename: • CMD /C sc delete AntiVirService – Filename: • CMD /C sc delete SbPF.Launcher – Filename: • CMD /C sc stop VSSERV – Filename: • sc config VSSERV start= disabled – Filename: • CMD /C sc config NOD32krn start= disabled – Filename: • CMD /C sc stop NOD32krn – Filename: • CMD /C net stop SPF4 – Filename: • CMD /C sc config PASRV start= disabled – Filename: • CMD /C net stop PASRV – Filename: • CMD /C net stop "avast! Antivirus" – Filename: • CMD /C net stop AntiVirService – Filename: • sc stop PASRV – Filename: • CMD /C sc stop PASRV – Filename: • sc delete "avast! Antivirus" – Filename: • net1 stop SbPF.Launcher – Filename: • net1 stop avg8wd – Filename: • sc delete avg8wd – Filename: • sc config NOD32krn start= disabled – Filename: • sc stop VSSERV – Filename: • CMD /C sc stop SPF4 – Filename: • CMD /C net stop NOD32krn – Filename: • sc stop "avast! Antivirus" – Filename: • net stop VSSERV – Filename: • net stop PASRV – Filename: • sc delete NOD32krn – Filename: • CMD /C sc config VSSERV start= disabled – Filename: • sc stop AntiVirService – Filename: • CMD /C sc delete avg8wd – Filename: • CMD /C sc config SbPF.Launcher start= disabled – Filename: • CMD /C net stop avg8wd – Filename: • net stop "avast! Antivirus" – Filename: • net1 stop PASRV – Filename: • sc config PASRV start= disabled – Filename: • CMD /C sc delete NOD32krn – Filename: • net1 stop NOD32krn Registry One of the following values is added in order to run the process after reboot: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "ctfmon.exe"="ctfmon.exe" The following registry keys are added: – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options\ctfmon.exe] • "Debugger"="wmispm.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\ Layers] • "%SYSDIR% \wmispm.exe"="DisableNXShowUI" The following registry keys are changed: – [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal] New value: • "ctfmon.exe"="ctfmon.exe" – [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network] New value: • "ctfmon.exe"="ctfmon.exe" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions] New value: • "GON"="%executed file% " IRC To deliver system information and to provide remote control it connects to the following IRC Server: Server: ascend.sr**********.info Port: 31960 Channel: #w1sd0m Nickname: [00|USA|XP|%number% ] File details Programming language: The malware program was written in Visual Basic.
Description inserted by Petre Galan on Thursday, April 8, 2010 Description updated by Petre Galan on Thursday, April 8, 2010
Back
.
.
.
.