Date discovered:20/01/2010
In the wild:Yes
Reported Infections:Low to medium
Distribution Potential:Low to medium
Damage Potential:Medium
Static file:Yes
File size:626.442 Bytes
MD5 checksum:ef524124ce636c95617cde6d151ae49f
IVDF version: - Wednesday, January 20, 2010

 General Method of propagation:
   • Autorun feature
   • Messenger

   •  Mcafee: W32/Palack.worm virus
   •  Panda: W32/IRCBot.CVV
   •  Eset: Win32/AutoRun.IRCBot.EM
   •  Bitdefender: Trojan.Generic.3013808

Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003

Side effects:
   • Drops malicious files
   • Third party control

 Files It copies itself to the following locations:
   • %WINDIR%\svchost.exe
   • %drive%\system.exe

The following files are created:

%drive%\autorun.inf This is a non malicious text file with the following content:
   • %code that runs malware%

– %HOME%\Application Data\Microsoft\Crypto\RSA\%CLSID%\af569e2015741bf1f8157a89c2ae5ce2_1c1a3893-4672-472f-afbd-f2c903f9947c

 Registry To each registry key one of the values is added in order to run the processes after reboot:

–  [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "Microsoft Corp"="%WINDIR%\svchost.exe"

–  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "Microsoft Corp"="%WINDIR%\svchost.exe"

The following registry key is added:

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\
   • "Microsoft Corp"="%WINDIR%\svchost.exe"

 Messenger It is spreading via Messenger. The characteristics are described below:

– MSN Messenger

The URL then refers to a copy of the described malware. If the user downloads and executes this file the infection process will start again.

 IRC To deliver system information and to provide remote control it connects to the following IRC Server:

Server: ee**********.info
Port: 4723
Channel: #EaGLeZ#
Nickname: EaGLeZ[USA][XP][00]%number%

 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

