Virus Characteristics
This is a file infecting VBScript virus that infects files with extension .htt, .htm, .html, .asp, .php and .jsp.
When run, it first checks the registry. If the following registry key value exists:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
"RegisteredOwner" = "Indonesian Today"
The virus will create the following registry key/value:
- HKEY_CURRENT_USER\Control Panel\International\
"s1159" = "Anti AS"
"s2359" = "Anti Shit"
"sTimeFormat" = "HH:mm:ss tt"
- HKEY_CURRENT_USER\Software\Classes\CLSID\
{20D04FE0-3AEA-1069-A2D8-08002B30309D}\" = "My Komputer"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
"RegisteredOwner" = "Indonesian Today"
"RegisteredOrganization" = "We love peace"
"OrgOrganization" = "Under Ground Indonesian"
"OrgOwner" = "We love peace!"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
"Hidden"= 1,"REG_DWORD"
- HKEY_CURRENT_USER\Software\MicrosoftWindows\CurrentVersion\Explorer\Advanced\
"HideFileExt" = 1
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\
Local Page" = "system\blank.htm"
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\
Start Page" = "system\blank.htm"
The virus copies itself to following location:
- %WinDir%\System\Blank.htm
- %WinDir%\Web\Folder.htt
- %WinDir%\System32\Folder.htt
- %WinDir%\Folder.htt
If above files exist, the virus will overwrite the files. It also modifies %WinDir%\Web\Webview.css file. When the folder option is set to web view, the virus body will be executed.
The virus searches the current folder for file of extension .htt, .htm, .html, .asp, .php, .jsp. If any file is found, it appends the virus body after the file content.
If the current date time is the 30th of even number month, it will rename the following files in the Windows directory:
- win.ini to won.chk
- system.ini to system.chk