Details:
Installation
This worm drops the following file(s):
- %System%\j3ewro.exe - copy of itself
- System%\JWEDSFDO0.DLL - also detected as WORM_ONLINEG.AFU
- %System%\revo.exe copy of itself
- %System%\revo0.dll detected as TSPY_OLGAME.MS
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Autostart Technique
This worm creates the following registry entry(ies) to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows
CurrentVersion\Run
jvsoft = "%System%\j3ewro.exe"
revo = "%System%\revo.exe"
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Other System Modifications
It modifies the following registry entry(ies) to hide files with both System and Read-only attributes:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\Advanced
Hidden = "2"
(Note: The default value data for the said registry entry is 1.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden = "0"
(Note: The default value data for the said registry entry is 1.)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue = "0"
(Note: The default value data for the said registry entry is 1.)
Propagation via Removable Drives
This worm drops copies of itself in all removable drives.
It drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.
The file AUTORUN.INF contains the following strings:
;{Garbage}
[AutoRun]
;{Garbage}
open=tj8odymw.exe
;{Garbage}
shell\open\Command=tj8odymw.exe
;{Garbage}
shell\open\Default=1
;{Garbage}
shell\explore\Command=tj8odymw.exe
;{Garbage}
;{ Garbage}
[AutoRun]
;{ Garbage}
open=t2yev.exe
;{ Garbage}
shell\ open\ Command= t2yev.exe
;{ Garbage}
shell\ open\ Default=1
;{ Garbage}
shell\ explore\ Command=t2yev.exe
;{ Garbage}
Download Routine
This worm accesses the following URLs to download the following .RAR files:
- http:// {BLOCKED}9.com/xjj/cc1.rar
- http:// {BLOCKED}7.com/xjj/cc.rar
- http://{BLOCKED}3.com/xrbv/uu1.rar
- http://{BLOCKED}3.com/xrbv/uu.rar
It then extracts the downloaded .RAR files which is detected as WORM_AUTORUN.BYT. It then executes the extracted file. As a result, malicious routines of the downloaded file may be exhibited on the affected system.
Affected Platforms
This worm runs on Windows 98, ME, NT, 2000, XP, and Server 2003.
Analysis By: Jasper Manuel
Revision History: