Признаки
При запуске создает следующие файлы:
* C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Explorer.exe
* %Windir%\system.exe
Копирует себя на все диски: в корне создает свою копию под именем auto.exe и файл автозапуска AUTORUN.INF.
Через реестр обеспечивает себе автозагрузку при каждом запуске Windows:
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe, System"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "C:\WINDOWS\system32\userinit.exe, System"
Создает следующие записи в реестре:
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bkav2006.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCAPP.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EGHOST.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FireTray.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEProt.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPLUS.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVCenter.kxp.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVFW.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVOL.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXp_1.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWATCHUI.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Kav.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KavPFW.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KpopMon.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Kvsrvxp.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MAILMON.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MCAGENT.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MCVSESCN.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSKAGENT.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvsvc32.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAVMON.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAVTIMER.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RRfwMain.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavService.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RfwMain.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rtvscan.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHSTAT.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TBMon.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpdaterUI.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VPTray.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdss.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\far.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icesword.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kav32.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavstart.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavsvc.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvolself.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvwsc.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\livesrv.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsserv.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\worm2007.exe\"Debugger" = "system.exe"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xcommsvr.exe\"Debugger" = "system.exe"
Заменяет стартовые URL для Yahoo! Messenger:
* HKEY_CURRENT_USER\Software\Yahoo\pager\View\YMSGR_ Launchcast\"content url" = "myebuddy.com"
* HKEY_CURRENT_USER\Software\Yahoo\pager\View\YMSGR_ buzz\"content url" = "myebuddy.com"
Отключает "Редактор реестра" и "Диспетчер задач":
* HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System\"DisableRegistryTools" = "1"
* HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System\"DisableTaskMgr" = "1"
* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\System\"DisableRegistryTools" = "1"
* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\System\"DisableTaskMgr" = "1"
Через реестр отключает ряд настроек "Проводника" и другие настройки, для сокрытия своего присутствия в системе:
* HKEY_CURRENT_USER\Software\Microsoft\Command Processor\"EnableExtensions" = "0"
* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Start Page" = "myebuddy.com"
* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\"PopupMgr" = "0"
* HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{282f98e4-c1d2-11db-8515-806d6172696f}\"BaseClass" = "Drive"
* HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{56999cec-3c1d-11db-a335-806d6172696f}\"BaseClass" = "Drive"
* HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{56999cef-3c1d-11db-a335-806d6172696f}\"BaseClass" = "Drive"
* HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer\"NoDriveTypeAutoRun" = "91"
* HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer\"NoFolderOptions" = "1"
* HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer\"NoRun" = "1"
* HKEY_CURRENT_USER\Software\Policies\Microsoft\Inte rnet Explorer\Control Panel\"Homepage" = "1"
* HKEY_CURRENT_USER\software\Microsoft\Windows\Curre ntVersion\Explorer\Advanced\"Hidden" = "2"
* HKEY_CURRENT_USER\software\Microsoft\Windows\Curre ntVersion\Explorer\Advanced\"HideFileExt" = "1"
* HKEY_CURRENT_USER\software\Microsoft\Windows\Curre ntVersion\Explorer\Advanced\"ShowSuperHidden" = "0"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Advanced\Folder\Hidden\SHOWALL \"CheckedValue" = "0"
* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Explorer\Shell Folders\"Common Startup" = "C:\Documents and Settings\All Users\Start Menu\Programs\Startup"
Пытается обновить себя через http, подключаясь к следующим URL:
* [
http://]72.232.141.84/~cgitnet/ledads/Change[???]
* [
http://]206.221.179.205/~ampedmed/Fo...tes/xand/upgra[???]
* [
http://]72.232.208.150/~aryacdc/images/toc[???]
* [
http://]72.232.108.82/~grimsby/images/butto[???]
* [
http://]216.246.30.66/~mkshost/forum...ubSilver/upgra[???]
* [
http://]72.232.141.84/~cgitnet/ledads/Change[???]
* [
http://]206.221.179.205/~ampedmed/Fo...tes/xand/upgra[???]
* [
http://]72.232.208.150/~aryacdc/images/toc[???]
* [
http://]72.232.108.82/~grimsby/images/butto[???]
Ведет удаленную статистику заражений, обращаясь к следующему URL:
* [
http://]70.86.197.82/~ohnishi/ranking/test[???]
Рассылает ссылки на себя через Yahoo! Instant Messenger:
* [
http://]72.232.141.84/~cgitnet/ledads/Change[???]
* [
http://]216.246.30.66/~mkshost/forum...ubSilver/upgra[???]
* [
http://]206.221.179.205/~ampedmed/Fo...tes/xand/upgra[???]
* [
http://]72.232.208.150/~aryacdc/images/toc[???]
* [
http://]72.232.108.82/~grimsby/images/butto[???]
* [
http://]216.246.30.66/~mkshost/forum...ubSilver/upgra[???]
Завершает процессы, содержащие следующие строки:
* BITDEFENDER
* BKAV
* ccEvtMgr
* ccProxy
* ccSetMgr
* D32
* Duba
* FireSvc
* GOOGLE.COM
* IceSword
* KPfwSvc
* KVSrvXP
* KVWSC
* McAfeeFramework
* McShield
* McTaskManager
* msctls_statusbar32
* MskService
* navapsvc
* NOD32
* NPFMntor
* RsCCenter
* RsRavMon
* Schedule
* sharedaccess
* SNDSrvc
* SPBBCSvc
* Symantec AntiVirus
* Symantec Core LC
* System Safety Monitor
* VirusScan
* Wrapped gift Killer
* wscsvc
ЗАЩИТА
* Отключить функцию "Восстановление системы" (для Windows ME и XP)
* Полностью проверить систему антивирусом с обновлённой базой сигнатур
* Удалить все ключи реестра, созданные вредоносной программой; восстановить изменённые настройки (использовать regedit.exe)
Действие
Червь для платформы Windows. Распространяется копированием на все диски и рассылкой через Yahoo! Instant Messenger.
Загружает дополнительный вредоносный код; прерывает антивирусные процессы.