Virus: TR/OnlineGam.103268 Date discovered: 03/11/2009 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low to medium Damage Potential: Low to medium Static file: Yes File size: 103.268 Bytes MD5 checksum: 617896d58fe10ce634ce88784725dbf1 IVDF version: 7.01.06.185 - Tuesday, November 3, 2009
General Method of propagation: • Autorun feature Aliases: • Sophos: Mal/EncPk-CE • Panda: W32/Lineage.IBZ • Eset: Win32/PSW.OnLineGames.NMY • Bitdefender: Trojan.Generic.1706555 Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads a malicious file • Drops malicious files • Lowers security settings • Registry modification Files It copies itself to the following locations: • %SYSDIR% \amvo.exe • %drive% \pa39xth.cmd It deletes the initially executed copy of itself. It deletes the following files: • %TEMPDIR% \help.rar • %TEMPDIR% \94r.sys The following files are created: – %drive% \autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %TEMPDIR% \kt.dll Further investigation pointed out that this file is malware, too. Detected as: TR/Crypt.XPACK.Gen – %TEMPDIR% \94r.sys Further investigation pointed out that this file is malware, too. Detected as: Rkit/Vanti.hl.1 – %SYSDIR% \amvo0.dll Further investigation pointed out that this file is malware, too. Detected as: TR/Vundo.Gen – %TEMPDIR% \help.rar It tries to download a file: – The location is the following: • http://www.om7890.com/mf2/********** It tries to executes the following file: – Filename: • "%PROGRAM FILES% \Internet Explorer\iexplore.exe" Registry The following registry key is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "amva"="%SYSDIR% \amvo.exe" The following registry key is added: – [HKLM\SOFTWARE\Classes\CLSID\MADOWN] • "urlinfo"="%character string% " The following registry keys are changed: Various Explorer settings: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] New value: • "Hidden"=dword:0x00000002 • "ShowSuperHidden"=dword:0x00000000 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] New value: • "NoDriveTypeAutoRun"=dword:0x00000091 – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ Folder\Hidden\SHOWALL] New value: • "CheckedValue"=dword:0x00000000 Injection – It injects the following file into a process: %SYSDIR% \amvo0.dll Process name: • explorer.exe – It injects itself as a remote thread into a process. Process name: • iexplore.exe File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Monday, May 10, 2010 Description updated by Petre Galan on Monday, May 10, 2010
Back
.
.
.
.