Infection Channel: Propagates via removable drives, Downloaded from the Internet, Dropped by other malware, Propagates via instant messaging applications
This worm arrives by connecting affected removable drives to a system. It arrives by accessing affected shared networks. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It uses Windows Task Scheduler to create a scheduled task that executes the dropped copy. It uses the default Windows folder icon to trick users into opening the file. Double-clicking the file executes this malware.
It drops an AUTORUN.INF file to automatically execute the copies it drops when a user accesses the drives of an affected system.
File size: 836,165 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 29 May 2010
Payload: Downloads files, Terminates processes
Arrival Details
This worm arrives by connecting affected removable drives to a system.
It arrives by accessing affected shared networks.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This worm drops the following copies of itself into the affected system:
- {install directory}\system3_.exe
It drops the following component file(s):
- {install directory}\autorun.ini - copy of autorun.inf
It uses Windows Task Scheduler to create a scheduled task that executes the dropped copy.
It uses the default Windows folder icon to trick users into opening the file. Double-clicking the file executes this malware.
Autostart Technique
This worm adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Yahoo Messengger = {install directory}\system3_.exe"
It modifies the following registry entries to ensure it automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Winlogon
Shell = "Explorer.exe system3_.exe"
(Note: The default value data of the said registry entry is Explorer.exe.)
The scheduled task executes the malware every:
Other System Modifications
This worm adds the following registry entries as part of its installation routine:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\
WorkgroupCrawler\Shares
shared = "\New Folder.exe"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Schedule
AtTaskMaxHours = "0"
It modifies the following registry key(s)/entry(ies) as part of its installation routine:
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
Start Page = "http://www.{BLOCKED}mworld.50webs.com "
(Note: The default value data of the said registry entry is {default}.)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Main
Default_Page_URL = "http://www.{BLOCKED}mworld.50webs.com "
(Note: The default value data of the said registry entry is {default}.)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Main
Default_Search_URL = "http://www.{BLOCKED}mworld.50webs.com "
(Note: The default value data of the said registry entry is {default search page}.)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Main
Search Page = "http://www.{BLOCKED}mworld.50webs.com "
(Note: The default value data of the said registry entry is {default}.)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Main
Start Page = "http://www.{BLOCKED}mworld.50webs.com "
(Note: The default value data of the said registry entry is {default}.)
Propagation
This worm searches for folders in all physical and removable drives then drops copies of itself inside the folder as {folder name}.EXE.
It drops the following copy of itself in all physical and removable drives:
It drops an AUTORUN.INF file to automatically execute the copies it drops when a user accesses the drives of an affected system.
The said .INF file contains the following strings:
[Autorun]
Open=system3_.exe
Shellexecute=system3_.exe
Shell\Open\command=system3_.exe
Shell=Open
It sends messages that contain links to sites hosting remote copies of itself using the following instant-messaging (IM) applications:
- Yahoo Messenger
- Google Talk
Process Termination
This worm terminates the following processes if found running in the affected system's memory:
Download Routine
This worm connects to the following URL(s) to download its configuration file:
- http://{BLOCKED}ay.com/asdb{1-50}/setting.ini
- http://{BLOCKED}u{1-25}.0catch.com/set/setting.ini
It saves the files it downloads using the following names:
- {install directory}\setting.ini
NOTES:
Upon execution, the malware checks the OS version of the affected machine. If it is Windows Vista, it sets the {install directory} to C:\Desktop or %User Temp%.
If the worm is not running on Windows Vista, the {install directory}is set to %System% or %Windows%.
This worm enumerates shared drives by checking the value from following registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares
It then copies itself to the shared drive as New Folder.exe. It also copies its corresponding AUTORUN.INF to automatically execute the worm.
It terminates processes of applications with the following Window Names:
- [FireLion]
- Bkav2006
- Registry
- System Configuration
- Windows Task
Connect with us on
| | | |