Virus Characteristics
| File Property | Property Value |
| FileName | !itw#17.exe |
| McAfee Artemis | Artemis!0e6f49ee3339
|
| McAfee Detection | Generic.dx!cbo |
| Length | 933,888 bytes |
| CRC | 63C60178 |
| MD5 | 0E6F49EE3339EA4C3A3C078FCEEFD030
|
| SHA1 | 92A9C1DAE4E825F62CAAEC7425CBD0FDBA6587DD
|
Other Common Detection Aliases
| Company Name | Detection Name |
| ahnlab | Win-Trojan/Genome.933888
|
| avast | Win32:Trojan-gen |
| AVG (GriSoft) | Generic_c.BIVU |
| Avira | TR/Crypt.XPACK.Gen |
| BitDefender | Trojan.Generic.2503539
|
| Eset | Win32/Agent.NGY |
| FortiNet | W32/Genome.S!tr |
| F-Prot | W32/Downldr2.GUUN |
| Kaspersky | Trojan-Downloader.Win32.Genome.cg
|
| microsoft | Worm:Win32/Neeris.gen!C
|
| norman | Smalltroj.QJSK |
| panda | Generic Trojan |
| Sophos | Mal/Generic-A |
| Symantec | W32.Netsky@mm |
| Trend Micro | TROJ_Generic.DIT |
| V-Buster | Worm.Pushbot.RJ |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
Modifies memory of other processes
| Critical |
Enumerates open windows
| Medium |
Enumerates running processes
| Medium |
Program often suspends itself
| Medium |
Uses shared memory of other processes
| Low |
Writes executable in the windows folder
| Low |
Creates registry keys and data values to persist on OS reboot
| Informational |
| Registers DLLs | Informational |
Other detections that have been observed.
| FileName | McAfee Supported |
| %WINDIR%\login.scr | Generic.dx!cbo |
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
%USERPROFILE%\local settings\temp\!itw#17.exe
The following files have been added to the system:
%ALLUSERSPROFILE%\application data\temp%TEMP%\perflib_perfdata_be8.dat%WINDIR%\login.scr
The following registry elements have been created:
HKEY_LOCAL_MACHINE\software\classes\clsid\{718e12f3-718e-12f3-718e-12f3718e12f3}\- (default) = outlook express mail object
- iimemsjhzdwn = _adcj_rm]nh]jbphevjcm~ddw@fpaj^
- iimemsjhzdwn = _qdcj_rm]^h]jbphevjcm~ddw@fpaj^
- mrgq = cpgkwrqfx\opvtkqg~ft
- pijcdltowguqi = `axzfkohhjxclthxdoocn
- pmruanmi = myjm{sgyubf|`fsj]d}ac~
- utzpfqzdedi = c{a\idtra_slfjp
- utzpfqzdedi = c{apidtraprov``
- xpvrsynjennra = ar@gncadijxl\hul~yi|yzkg~`wp}n_o
- zkyvdtm = x|iysqppe~z{vwh~m
HKEY_LOCAL_MACHINE\software\classes\clsid\{718e12f3-718e-12f3-718e-12f3718e12f3}\inprocserver32\- (default) = %programfiles%\outlook express\msoe.dll
- threadingmodel = apartment
HKEY_LOCAL_MACHINE\software\licenses\- {08aa7e1ecc2280058} = [binary data]
- {i8aa7e1ecc2280058} = 1
- {i8aa7e1ecc2280058} = 2
- {i8aa7e1ecc2280058} = 3
- {i8aa7e1ecc2280058} = 4
- {i8aa7e1ecc2280058} = 5
- {i8aa7e1ecc2280058} = 6
- {k7c0db872a3f777c0} = [binary data]
- {r7c0db872a3f777c0} = 345626
HKEY_LOCAL_MACHINE\Software\Microsoft\rfc1156agent\currentversion\parameters\- trappolltimemillisecs = 1080
The following registry elements have been changed:
HKEY_LOCAL_MACHINE\Software\Microsoft\wbem\wdm\- c:\windows\system32\advapi32.dll[mofresourcename] = lowdatetime
:341368832,highdatetime:29436808***binary mof compiled successfully
- c:\windows\system32\dnsapi.dll[mofresource] = lowdatetime:341368832
,highdatetime:29436808***binary mof compiled successfully
- c:\windows\system32\drivers\acpi.sys[acpimofresource] = lowdatetime
:341368832,highdatetime:29436808***binary mof compiled successfully
- c:\windows\system32\drivers\processr.sys[processorwmi] = lowdatetime
:341368832,highdatetime:29436808***binary mof compiled successfully
- c:\windows\system32\kerberos.dll[mof_resource] = lowdatetime:341368832
,highdatetime:29436808***binary mof compiled successfully
- c:\windows\system32\lsass.exe[lsamofresource] = lowdatetime:341368832
,highdatetime:29436808***binary mof compiled successfully
- c:\windows\system32\msv1_0.dll[mofresource] = lowdatetime:341368832
,highdatetime:29436808***binary mof compiled successfully
- c:\windows\system32\netlogon.dll[mofresource] = lowdatetime:341368832
,highdatetime:29436808***binary mof compiled successfully
- c:\windows\system32\spoolsv.exe[spooler] = lowdatetime:341368832
,highdatetime:29436808***binary mof compiled successfully
The applications created the following network connection(s):
************:44443 (irc)- PASS bootforfun
NICK [USA|00|P|03039]
- PASS bootforfun
NICK [USA|00|P|03039]
USER XP-4644 * 0 :VMG-CLIENT
http- hxxp://172.16.199.200/img/funny/**************