Virus: TR/Vundo.IS Date discovered: 24/07/2008 Type: Trojan In the wild: No Reported Infections: Low Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 93.184 Bytes MD5 checksum: ac0B91f457566dfbdaeb0904946aa1c4 IVDF version: 7.00.05.160 - Thu, 24 Jul 2008 08:15 (GMT+1)
General Method of propagation: • No own spreading routine Alias: • Mcafee: Vundo trojan Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Drops files • Registry modification • Third party control Files The following files are created: – Non malicious files: • %malware execution directory% \%random character string% .tmp • %malware execution directory% \%random character string% .ini Registry The following registry key is added in order to run the process after reboot: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "%hex values% "="rundll32.exe \"%malware execution directory% \%malware dll% ",b" The following registry keys are added: – [HKLM\SOFTWARE\Microsoft\%hex values% ] • @="%hex values% " • "red_srv"="%internet resources used by malware% " • "red_srv_bckp"="%internet resources used by malware% " – [HKLM\SOFTWARE\Microsoft\aoprndtws] • @="%generated CLSID% " – [HKCU\Software\Microsoft\rdfa] • "F"=hex:30,00 • "N"=hex:30,00 Backdoor Contact server: The following: • http://regters.********** As a result it may send information and remote control could be provided. Injection – It injects itself into a process. Process name: • explorer.exe File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.See a brief description here . Description inserted by Andreas Feuerstein on Wed, 30 Jul 2008 09:28 (GMT+1) Description updated by Andreas Feuerstein on Wed, 30 Jul 2008 12:33 (GMT+1)