Virus: TR/Fake.Rean.2005 Date discovered: 19/05/2011 Type: Trojan In the wild: Yes Reported Infections: Low Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 331.776 Bytes MD5 checksum: 6C8F4A2E79196801A44E3A3FE0A82EB3 VDF version: 7.11.08.67 - Thursday, May 19, 2011IVDF version: 7.11.08.67 - Thursday, May 19, 2011
General Method of propagation: • No own spreading routine Aliases: • TrendMicro: TROJ_FAKEAV.SMIN • Sophos: Mal/Behav-321 • Microsoft: Rogue:Win32/FakeRean Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 • Windows Vista • Windows 7 Side effects: • Blocks access to security websites • Drops files • Lowers security settings • Registry modification Right after execution the following information is displayed: Files It copies itself to the following location: • %HOME%\Local Settings\Application Data\%random character string% .exe It deletes the initially executed copy of itself. The following files are created: – %TEMPDIR% \en122h3o5146q55we582o122u34a10gj5076v5w33es4i2 – %ALLUSERSPROFILE%\Application Data\en122h3o5146q55we582o122u34a10gj5076v5w33es4i2 – %HOME%\Local Settings\Application Data\en122h3o5146q55we582o122u34a10gj5076v5w33es4i2 – %TEMPDIR% \en122h3o5146q55we582o122u34a10gj5076v5w33es4i2 – %HOME%\Templates\en122h3o5146q55we582o122u34a10gj5076v5w33es4i2 Registry The following registry keys are added: – [HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile] • "DoNotAllowExceptions"=dword:00000000 • "EnableFirewall"=dword:00000000 • "DisableNotifications"=dword:00000001 – [HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\ FirewallPolicy\DomainProfile] • "EnableFirewall"=dword:00000000 • "DoNotAllowExceptions"=dword:00000000 • "DisableNotifications"=dword:00000001 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "ctfmon.exe"="%SYSDIR% \ctfmon.exe" – [HKCR\.exe\shell\open\command] • "(Default)"="\"%HOME%\Local Settings\Application Data\\%random character string% .exe\" -a \"%1\" %*" • "IsolatedCommand"="\"%1\" %*" – [HKCR\exefile\shell\open\command] • "(Default)"="\"%HOME%\Local Settings\Application Data\\%random character string% .exe\" -a \"%1\" %*" • "IsolatedCommand"="\"%1\" %*" – [HKCR\exefile\shell\runas\command] • "(Default)"="\"%1\" %*" • "IsolatedCommand"="\"%1\" %*" – [HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\ command] • "(Default)"="\"%HOME%\Local Settings\Application Data\\%random character string% .exe\" -a \"%PROGRAM FILES% \Intern" The following registry key is changed: – [HKLM\SOFTWARE\Microsoft\Security Center] New value: • "AntiVirusDisableNotify"=dword:00000001 • "FirewallDisableNotify"=dword:00000001 • "FirewallOverride"=dword:00000001 • "UpdatesDisableNotify"=dword:00000001 • "AntiVirusOverride"=dword:00000001 Injection – It injects itself as a remote thread into a process. Process name: • iexplore.exe Miscellaneous Accesses internet resources: • **********oripuqoxyl.com/1017000412; **********igomyqeg.com/1017000412; **********ipabamefuw.com/1017000412; **********yziriryvi.com/1017000412; **********ipemura.com/1017000412; **********awekugygil.com/1017000412; **********ifyzadiby.com/1017000412; **********olalat.com/1017000412; **********ylocimemyja.com/1017000412; **********epelihyzex.com/1017000412; **********ijinymut.com/1017000412; **********uwemixonav.com/1017000412; **********exynogemi.com/1017000412; **********elaticik.com/1017000412; **********inolecowary.com/1017000412; **********ofociv.com/1017000412; **********ucerybaqecy.com/1017000412; **********upowibi.com/1017000412; **********ujykolenuja.com/1017000412; **********exyhun.com/1017000412; **********oralipijago.com/1017000412; **********idehecyty.com/1017000412; **********evepapucof.com/1017000412; **********ykacagatet.com/1017000412; **********ulipum.com/1017000412; **********isesyf.com/1017000412; **********ityvik.com/1017000412; **********ejutyhyfu.com/1017000412; **********usaseda.com/1017000412; **********ehiqino.com/1017000412; **********ynufyk.com/1017000412; **********udizoni.com/1017000412; **********evanyxora.com/1017000412; **********idicawisos.com/1017000412; **********ibipaj.com/1017000412; **********ixydyf.com/1017000412; **********unemymyko.com/1017000412; **********upinycom.com/1017000412; **********ygizeq.com/1017000412; **********emolezala.com/1017000412; **********eriwihat.com/1017000412; **********ecolun.com/1017000412; **********onabubi.com/1017000412
Description inserted by Andrei Ilie on Tuesday, August 16, 2011 Description updated by Andrei Ilie on Tuesday, August 16, 2011
Back
.
.
.
.