Date discovered:23/02/2010
In the wild:Yes
Reported Infections:Low to medium
Distribution Potential:Medium
Damage Potential:Low to medium
Static file:Yes
File size:254.471 Bytes
MD5 checksum:3701f5e0e1382174ba97821d15a69fde
IVDF version:

 General Methods of propagation:
   • Autorun feature
   • Messenger
   • Peer to Peer

   •  Sophos: Troj/Nyrate-L
   •  Bitdefender: Backdoor.Tofsee.Gen
   •  Panda: W32/P2Pworm.GF
   •  Eset: Win32/Peerfrag.EC

Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003

Side effects:
   • Drops malicious files
   • Registry modification

 Files It copies itself to the following locations:
   • %drive%\vircure\vircure32.exe
   • %recycle bin%\%CLSID%\MsMxEng.exe

The following files are created:

%recycle bin%\%CLSID%\Desktop.ini
%drive%\autorun.inf This is a non malicious text file with the following content:
   • %code that runs malware%

 Registry The following registry key is added in order to run the process after reboot:

– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   • "Taskman"="%recycle bin%\%CLSID%\MsMxEng.exe"

 P2P In order to infect other systems in the Peer to Peer network community the following action is performed:   It searches for directories that contain one of the following substrings:
   • Software\BearShare\General
   • Software\iMesh\General
   • Software\Shareaza\Shareaza\Downloads
   • Software\Kazaa\LocalContent
   • Software\DC++
   • Software\eMule
   • Software\Microsoft\Windows\CurrentVersion\Uninstall\eMule Plus_is1

   It searches for the following standard share:
   • \Local Settings\Application Data\Ares\My Shared Folder

 Messenger It is spreading via Messenger. The characteristics are described below:

– Windows Live Messenger

The URL then refers to a copy of the described malware. If the user downloads and executes this file the infection process will start again.

 IRC To deliver system information and to provide remote control it connects to the following IRC Server:

Server: coupemx.rvs**********.com
Port: 7663
Channel: #Barby-G1rl2#
Nickname: [MAY|USA|00|P|%number%]

 Backdoor The following ports are opened:

– dig**********.cn on UDP port 44420
– 77.79.**********.71 on UDP port 10023

 Injection – It injects itself as a remote thread into a process.

    Process name:
   • explorer.exe

 Miscellaneous Mutex:
It creates the following Mutex:
   • sereirijtrrejirrrr

 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Description inserted by Petre Galan on Friday, October 22, 2010
Description updated by Petre Galan on Friday, October 22, 2010

