Virus: TR/PSW.Onlineg.ALZR Date discovered: 05/03/2009 Type: Trojan In the wild: Yes Reported Infections: Medium Distribution Potential: Medium Damage Potential: Medium Static file: Yes File size: 168.420 Bytes MD5 checksum: 42438a0F0D9501bf1370287ff4b451bd IVDF version: 7.01.02.122 - Thursday, March 5, 2009
General Aliases: • Symantec: Infostealer.Gampass • Mcafee: Generic PWS.ak trojan !!! • Kaspersky: Trojan.Win32.Agent2.eij • Sophos: Mal/EncPk-HI • Panda: W32/Lineage.KYR • Eset: Win32/PSW.OnLineGames.NMY • Bitdefender: Trojan.PWS.OnLineGames.KCND Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files • Drops malicious files • Lowers security settings • Registry modification Files It copies itself to the following locations: • %drive% \d8k6hg.com • %SYSDIR% \kva8wr.exe It overwrites a file. – %SYSDIR% \drivers\cdaudio.sys It deletes the initially executed copy of itself. It deletes the following file: • %SYSDIR% \drivers\cdaudio.sys The following files are created: – %drive% \autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %drive% \gjnfah.cmd (176444) Further investigation pointed out that this file is malware, too. Detected as: TR/Crypt.ZPACK.Gen – %SYSDIR% \ahnsbsb.exe (176444) Detected as: TR/Crypt.ZPACK.Gen – %SYSDIR% \bgotrtu0.dll (73728) Detected as: TR/PSW.OnLin.ALZR.1 – %SYSDIR% \ahnfgss0.dll (88576) Detected as: TR/Crypt.ZPACK.Gen – %SYSDIR% \uweyiwe0.dll (97280) Detected as: TR/Crypt.XPACK.Gen – %SYSDIR% \ahnxsds0.dll (81920) Detected as: TR/Crypt.ZPACK.Gen It tries to download some files: – The location is the following: • http://yklop.com/xhg2/********** Further investigation pointed out that this file is malware, too. – The location is the following: • http://kioytrfd.com/xhg2/********** Registry The following registry key is added in order to run the process after reboot: – [HKLM\SYSTEM\CurrentControlSet\Services\AVPsys] • "Start"=dword:0x3 • "Type"=dword:0x1 • "ImagePath"="\??\%SYSDIR% \drivers\cdaudio.sys" • "DisplayName"="AVPsys" • "ErrorControl"=dword:0x1 One of the following values is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "ahnsoft"="%SYSDIR% \ahnsbsb.exe" • "kvasoft"="%SYSDIR% \kva8wr.exe" It registers a browser helper object (BHO) by adding the following keys: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}] – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{F171A450-7AF5-43E1-AFED-EDC826A1B0F5}] The following registry keys are added: – [HKLM\SOFTWARE\Classes\CLSID\MNDOWN] • "urlinfo"="m1chgt.e" – [HKLM\SOFTWARE\Classes\CLSID\ {238C32AB-955D-4707-AAB9-C9B3AB8D4225}] • "(default)"="IEHlprObj Class" – [HKLM\SOFTWARE\Classes\CLSID\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\ InprocServer32] • "ThreadingModel"="Apartment" • "(default)"="%SYSDIR% \ahnxsds0.dll" – [HKLM\SOFTWARE\Classes\CLSID\{238C32AB-955D-4707-AAB9-C9B3AB8D4225}\ ProgID] • "(default)"="IEHlprObj.IEHlprObj.1" – [HKLM\SOFTWARE\Classes\Interface\ {238C32AC-955D-4707-AAB9-C9B3AB8D4225}] • @="IIEHlprObj" – [HKLM\SOFTWARE\Classes\Interface\ {238C32AC-955D-4707-AAB9-C9B3AB8D4225}\ProxyStubClsid] • @="{00020424-0000-0000-C000-000000000046}" – [HKLM\SOFTWARE\Classes\Interface\ {238C32AC-955D-4707-AAB9-C9B3AB8D4225}\ProxyStubClsid32] • @="{00020424-0000-0000-C000-000000000046}" – [HKLM\SOFTWARE\Classes\Interface\ {238C32AC-955D-4707-AAB9-C9B3AB8D4225}\TypeLib] • "Version"="1.0" • @="{238C32A2-955D-4707-AAB9-C9B3AB8D4225}" – [HKLM\SOFTWARE\Classes\Interface\ {F171A44F-7AF5-43E1-AFED-EDC826A1B0F5}] • @="IIEHlprObj" – [HKLM\SOFTWARE\Classes\Interface\ {F171A44F-7AF5-43E1-AFED-EDC826A1B0F5}\ProxyStubClsid] • @="{00020424-0000-0000-C000-000000000046}" – [HKLM\SOFTWARE\Classes\Interface\ {F171A44F-7AF5-43E1-AFED-EDC826A1B0F5}\ProxyStubClsid32] • @="{00020424-0000-0000-C000-000000000046}" – [HKLM\SOFTWARE\Classes\Interface\ {238C32AC-955D-4707-AAB9-C9B3AB8D4225}\TypeLib] • Version"="1.0" • @="{238C32A2-955D-4707-AAB9-C9B3AB8D4225}" – [HKLM\SOFTWARE\Classes\Interface\ {F171A44F-7AF5-43E1-AFED-EDC826A1B0F5}] • @="IIEHlprObj" – [HKLM\SOFTWARE\Classes\Interface\ {F171A44F-7AF5-43E1-AFED-EDC826A1B0F5}\ProxyStubClsid] • @="{00020424-0000-0000-C000-000000000046}" – [HKLM\SOFTWARE\Classes\Interface\ {F171A44F-7AF5-43E1-AFED-EDC826A1B0F5}\ProxyStubClsid32] • @="{00020424-0000-0000-C000-000000000046}" – [HKLM\SOFTWARE\Classes\Interface\ {F171A44F-7AF5-43E1-AFED-EDC826A1B0F5}\TypeLib] • "Version"="1.0" • @="{F171A442-7AF5-43E1-AFED-EDC826A1B0F5}" – [HKLM\SOFTWARE\Classes\TypeLib\ {238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0] • @="IEHelper 1.0 Type Library" – [HKLM\SOFTWARE\Classes\TypeLib\ {238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\0\win32] • @="%SYSDIR% \ahnxsds0.dll" – [HKLM\SOFTWARE\Classes\TypeLib\ {238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\FLAGS] • @="0" – [HKLM\SOFTWARE\Classes\TypeLib\ {238C32A2-955D-4707-AAB9-C9B3AB8D4225}\1.0\HELPDIR] • @="%SYSDIR% \" – [HKLM\SOFTWARE\Classes\TypeLib\ {F171A442-7AF5-43E1-AFED-EDC826A1B0F5}\1.0] • @="IEHelper 1.0 Type Library" – [HKLM\SOFTWARE\Classes\TypeLib\ {F171A442-7AF5-43E1-AFED-EDC826A1B0F5}\1.0\0\win32] • @="%SYSDIR% \bgotrtu0.dll" – [HKLM\SOFTWARE\Classes\TypeLib\ {F171A442-7AF5-43E1-AFED-EDC826A1B0F5}\1.0\FLAGS] • @="0" – [HKLM\SOFTWARE\Classes\TypeLib\ {F171A442-7AF5-43E1-AFED-EDC826A1B0F5}\1.0\HELPDIR] • @="%SYSDIR% \" The following registry keys are changed: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ Folder\Hidden\SHOWALL] New value: • "CheckedValue"=dword:0x0 – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] New value: • "Hidden"=dword:0x2 • "ShowSuperHidden"=dword:0x0 Injection – It injects the following file into a process: %SYSDIR% \ahnfgss0.dll Process name: • %all running processes% File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Descrição enviada por Petre Galan em
segunda-feira, 19 de outubro de 2009 Descrição atualizada por Petre Galan em
segunda-feira, 19 de outubro de 2009
Voltar
.
.
.
.