Precisa de ajuda? Peça à comunidade ou contrate um perito.
Acesse a Avira Answers
Date discovered:16/08/2010
In the wild:Yes
Reported Infections:Low to medium
Distribution Potential:Medium
Damage Potential:Low to medium
Static file:Yes
File size:565.346 Bytes
MD5 checksum:3bb7ee908bd9adaf7449f02d71d60306
VDF version:
IVDF version: - Monday, August 16, 2010

 General Methods of propagation:
    Autorun feature
   • Peer to Peer

   •  Mcafee: W32/Autorun.worm.zf.gen
   •  Bitdefender: Trojan.Generic.4701653
   •  Panda: W32/Harakit.ER
   •  Eset: Win32/Tifaut.A

Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003

Side effects:
   • Downloads a malicious file
   • Drops malicious files
   • Lowers security settings
   • Registry modification

 Files It copies itself to the following locations:
   • %SYSDIR%\csrcs.exe
   • %SYSDIR%\14412531.exe
   • %drive%\csrcs.exe

It deletes the initially executed copy of itself.

It deletes the following files:
   • %SYSDIR%\accwiz.exe
   • %SYSDIR%\access.cpl
   • %SYSDIR%\$winnt$.inf
   • %TEMPDIR%\iwrohim
   • %TEMPDIR%\nnbjcnk
   • %SYSDIR%\aaaamon.dll
   • %TEMPDIR%\~ip.tmp
   • %SYSDIR%\acctres.dll
   • %SYSDIR%\12520850.cpx
   • %SYSDIR%\12520437.cpx
   • %SYSDIR%\acledit.dll
   • %SYSDIR%\aclui.dll
   • %SYSDIR%\aaclient.dll
   • %SYSDIR%\6to4svc.dll

The following file is created:

%drive%\autorun.inf This is a non malicious text file with the following content:
   • %code that runs malware%


It tries to download a file:

The location is the following:
It is saved on the local hard drive under: %temporary internet files%\xny[1].htm

It tries to execute the following file:

   • %SYSDIR%\csrcs.exe

 Registry The following registry keys are added in order to run the processes after reboot:

   • "csrcs"="%SYSDIR%\csrcs.exe"

   • "csrcs"="%SYSDIR%\csrcs.exe"

–  [HKLM\Software\Microsoft\DRM\amty]
   • fir

The following registry key is added:

   • "bwp2"="noneed"
   • "cb3"="noneed"
   • "dreg"="408406541BC5BBE4DC197A2A0C46B9ACF2F90D96B151D7C7BCBD177641EE95F562E634D70EB70FB65FC8FBF0EC31261C8626D05B1ED70CC881A48DA07A7E1A9A"
   • "exp1"="408406541BC5BBE4DC197A2A0C46B9A8F2F90D96B151D7C7BCBD177641EE95F5"
   • "ilop"="1"
   • "kiu"="408406541BC5BBE4DC197A2A0C46B9AFF2F90D96B151D7C7BCBD177741EE958C62E634D70EB773B95FC8FBF0EC31261B8626D05B1ED70CC981A58DD77A7E64EBE121A6249AF4EF57624A6F9892029D504AF01C82DA09AF8C1E11E7C7C1DBB0E4C73A32413AEDD017317B4DD6134930AFBED5B4DE9732DD170CBA2B3D5055F2C5FAEBD5B5E320E57FAC7FF1B2E72784568EE6B66EBA34598D9DCBC155626987AC3FDCA60253FBE2E44B511E5AB957FD1A279E1A156BE3D057430F95C77B73E25AA592466217DE3CB8135AF486B8FFD8138B7490B696B777E429C0A0619658E4A44BEFB49C04967F02EF5BD2C14F82440C9BCDDD932103EA89479138700DFF6A4A"
   • "p1"="1"

The following registry keys are changed:

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   New value:
   • "Shell"="Explorer.exe csrcs.exe"

   New value:
   • "Hidden"=dword:0x00000002
   • "ShowSuperHidden"=dword:0x00000000
   • "SuperHidden"=dword:0x00000000

   New value:
   • "CheckedValue"=dword:0x00000001

 P2P In order to infect other systems in the Peer to Peer network community the following action is performed:

   It retrieves shared folders by querying the following registry keys:
   • HKCU\Software\Kazaa\LocalContent
   • HKCU\Software\Shareaza\Shareaza

 Backdoor Contact server:
All of the following:
   • www.5eb**********.com:82 (TCP)
   • 95.211.**********.184:89 (TCP)
   •**********?v=%number%&id=%character string%

 Miscellaneous  Checks for an internet connection by contacting the following web sites:
   • string%&rnd2=%character string%
Accesses internet resources:
   • http://geoloc.dai**********.com/?self

It creates the following Mutex:
   • df8g1sdf68g18er1g8re16

 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Descrição enviada por Petre Galan em terça-feira, 1 de março de 2011
Descrição atualizada por Andrei Ivanes em sexta-feira, 4 de março de 2011

Voltar . . . .
https:// Esta janela é criptografada para sua segurança.