Infection Channel: Dropped by other malware, Downloaded from the Internet, Propagates via removable drives
This worm arrives via removable drives. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It uses the default Windows folder icon to trick users into opening the file. Double-clicking the file executes this malware.
It sends gathered information to a predetermined email address using its own Simple Mail Transfer Protocol (SMTP) engine.
File size: 1,615,360 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 03 Oct 2012
Arrival Details
This worm arrives via removable drives.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This worm drops the following copies of itself into the affected system:
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
It uses the default Windows folder icon to trick users into opening the file. Double-clicking the file executes this malware.
Autostart Technique
This worm adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
gtalkupdate = "%User Profile%\gupd.exe"
Other System Modifications
This worm adds the following registry entries as part of its installation routine:
HKEY_CURRENT_USER\Software\Chilkat Software, Inc.\
ChilkatMail
Key30 = "{random characters}"
HKEY_LOCAL_MACHINE\SOFTWARE\Chilkat Software, Inc.\
ChilkatMail
Key30 = "{random characters}"
It adds the following registry keys as part of its installation routine:
HKEY_CURRENT_USER\Software\Chilkat Software, Inc.
HKEY_CURRENT_USER\Software\Chilkat Software, Inc.\
ChilkatMail
HKEY_LOCAL_MACHINE\SOFTWARE\Chilkat Software, Inc.
HKEY_LOCAL_MACHINE\SOFTWARE\Chilkat Software, Inc.\
ChilkatMail
Propagation
This worm drops the following copy(ies) of itself in all removable drives:
- essay.exe
- lecture notes.exe
- portfolio.exe
Stolen Information
This worm sends gathered information to a predetermined email address using its own Simple Mail Transfer Protocol (SMTP) engine.
Other Details
This worm connects to the following URL(s) to check for an Internet connection:
- http://www.google.com/index.html
NOTES:
Upon execution, it checks for its existence by querying the value of HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\gtalkupdate.
Connect with us on
| | | |