Virus Characteristics
| File Property | Property Value |
| FileName | 1dymenjs.exe |
| McAfee Artemis | Artemis!8d4c252897a3
|
| McAfee Detection | W32/Autorun.worm |
| Length | 108,032 bytes |
| CRC | 287C0895 |
| MD5 | 8D4C252897A3BE33055578EF67C08541
|
| SHA1 | 3F7D8D34102978AC1A06775F8CE97A3022CCF284
|
Other Common Detection Aliases
| Company Name | Detection Name |
| avast | Win32:AutoRun-AIQ [Wrm]
|
| AVG (GriSoft) | Generic10.TMU (Trojan horse)
|
| Avira | TR/Autorun.acb |
| BitDefender | Worm.Rokshak.A |
| clamav | Worm.Autorun-1109 |
| Dr.Web | Win32.HLLW.Autoruner.6316
|
| Eset | Win32/AutoRun.MC worm
|
| FortiNet | W32/AutoRun.DRY!worm
|
| F-Prot | W32/Worm.VMC |
| Kaspersky | Worm.Win32.AutoRun.dry
|
| microsoft | worm:win32/rokhshah.a
|
| norman | W32/AutoRun.RON |
| panda | W32/AutoRun.DJ.worm |
| Sophos | Mal/Generic-A |
| Symantec | W32.SillyFDC |
| vba32 | Worm.Win32.AutoRun.dry
|
| V-Buster | Worm.AutoRun.dqw |
Vet (Computer Associates)
| Win32/Rokshah.A |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
Enumerates running processes
| Medium |
Uses shared memory of other processes
| Low |
Other detections that have been observed.
| FileName | McAfee Supported |
%WINDIR%\system32\service.exe
| W32/Autorun.worm |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
%USERPROFILE%\local settings\temp\1dymenjs.exe
The following files have been added to the system:
%WINDIR%\system32\autorun.inf%WINDIR%\system32\explorer.exe%WINDIR%\system32\service.exe
The following registry elements have been created:
HKEY_CURRENT_USER\software\service\HKEY_LOCAL_MACHINE\software\service\
The following registry elements have been changed:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\currentversion\run\- network services = c:\windows\system32\service.exe