Wednesday, January 21, 2009

Win32Autorun.cc

Virus: Win32Autorun.cc
Type: Trojan
In the wild: No
Reported Infections: Low
Distribution Potential: Low
Damage Potential: Low to medium
Static file: Yes
File size: 47.5 kb

Method of propagation:
• The malware spreads itself by creating "Autorun .inf" and a \sahit9\"lsass.exe" onto hard drive partitions,including removable media(eg flsh disk, memory card).
It hides the autorun.inf by changing its file attributes

Aliases:
• Kaspersky: Virus.Win32.Autorun
• F-Secure: Virus.Win32.VB.bg
• Grisoft: Worm/VB.ZU
• Eset: Win32/VB.DA

Platforms / OS:
• Windows 98
• Windows 98 SE
• Windows NT
• Windows ME
• Windows 2000
• Windows XP
• Windows 2003

Side effects:
• Drops files
• Lowers security settings
• Registry modification
• Eject itself to every file with the following extension .Doc

Files It copies itself to the following locations:

• %SYSDIR%\" mako9.inf"
• %SYSDIR%\kudar9\smss.exe
• %SYSDIR%\kudar9\services.exe
• %SYSDIR%\kudar9\lsass.exe
• %drive%\sahit9\"lsass.exe"

It creates the following directory:
• %drive%\sahit9

The following files are created:

– %WINDIR%\msvbvm60.dll
– %SYSDIR%\msvbvm60.dll

Registry The following registry keys are added in order to run the processes after reboot:

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
•c:\Baat.txt


The following registry keys are changed:

– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
Old value:
• "Shell"="Explorer.exe"
• "Userinit"="%SYSDIR%\userinit.exe"
New value:
• "System"="Explorer.exe "%SYSDIR%\kudar9\services.exe
• "Userinit"="%SYSDIR%\kudar9\services.exe"

– [HKCR\exefile]
Old value:
• @="Application"
New value:
• @="File"


– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug]
Old value:
• "Auto"="1"
• "Debugger"="drwtsn32 -p %ld -e %ld -g"
New value:
• "Auto"="1"
• "Debugger"="%SYSDIR%\kudar9\services.exe"

Various Explorer settings:
– [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
Old value:
• "Hidden"=%user defined settings%
• "HideFileExt"=%user defined settings%
• "ShowSuperHidden"=%user defined settings%
New value:
• "Hidden"=dword:00000000
• "HideFileExt"=dword:00000001
• "ShowSuperHidden"=dword:00000000

– [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot]
Old value:
• "AlternateShell"="cmd.exe"
New value:
• "AlternateShell"="%SYSDIR%\kudar9\services.exe"

– [HKCR\lnkfile\shell\open\command]
Old value:
• @=" "%1" %*"
New value:
• @=" "%SYSDIR%\kudar9\services.exe" "%1" %*"

– [HKCR\piffile\shell\open\command]
Old value:
• @=""%1" %*"
New value:
• @="%SYSDIR%\kudar9\services.exe"" "%1" %*"

– [HKCR\batfile\shell\open\command]
Old value:
• @=""%1" %*"
New value:
• @="%SYSDIR%\kudar9\services.exe" "%1" %*"

– [HKCR\comfile\shell\open\command]
Old value:
• @=""%1" %*"
New value:
• @="%SYSDIR%\kudar9\services.exe" "%1" %*"

Disable Regedit and Task Manager:
– [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
Old value:
• "DisableCMD"=%user defined settings%
• "DisableTaskMgr"=%user defined settings%
• "DisableRegistryTools"=%user defined settings%
New value:
• "DisableCMD"=dword:00000001
• "DisableTaskMgr"=dword:00000001
• "DisableRegistryTools"=dword:00000001

Various Explorer settings:
– [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
Old value:
• "NoFolderOptions"=%user defined settings%
New value:
• "NoFolderOptions"=dword:00000001

– [HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
Old value:
• "DisableConfig"=%user defined settings%
• "DisableSR"=%user defined settings%
New value:
• "DisableConfig"=dword:00000001
• "DisableSR"=dword:00000001

– [HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer]
New value:
• "LimitSystemRestoreCheckpointing"=dword:00000001
• "DisableMSI"=dword:00000001

– [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
CabinetState]
New value:
• "FullPathAddress"=dword:00000001

Process termination List of processes that are terminated:
• regedit.exe; AVP.exe; rtvscan.exe; NAV.exe; VSHWIN32.exe;
ProcessManager.exe; RegistryEditor.exe; Msiexec.exe; avgemc.exe;
nvcoas.exe; mcvsescn.exe; firefox.exe; TASKMGR.EXE; setup.exe;
Opera.exe; avguad.exe.; avgnt.exe; killvb.exe; Msi.exe

Processes with one of the following strings are terminated:
• ANT; BRO; VIR; TASK; REG; ASM; DBG; W32; BUG; HEX; DETEC; PROC; WALK;
REST; AVS; OPTIONS; AVG; SYMANTEC; PANDA; MCAFEE; PC-CILLIN; F-PROT;
KASPERSKY; VAKSIN; ANTI; VIRUS

Processes containing one of the following window titles are terminated:
• RegEdit_RegEdit
• Registry Editor
• Folder Options
• Local Settings


The following service is disabled:
• System Restore

Programming language:
•The malware program was written in Visual Basic.

No comments:

Post a Comment