Virus Characteristics
| File Property | Property Value |
| FileName | !itw#700.exe |
| McAfee Artemis | Artemis!fcdeaa9e5770
|
| McAfee Detection | PWS-Gamania.gen.a |
| Length | 99,004 bytes |
| CRC | 44BC477B |
| MD5 | FCDEAA9E5770815BC8C0498F2226FAD0
|
| SHA1 | 9E4AD556DFE0CD87041E214C0D35ED5577D42D54
|
Other Common Detection Aliases
| Company Name | Detection Name |
| ahnlab | Dropper/OnlineGameHack.99004
|
| avast | Win32:Monga [Trj] |
| AVG (GriSoft) | PSW.OnlineGames.2.S |
| Avira | TR/Crypt.XPACK.Gen |
| BitDefender | Packer.Malware.NSAnti.DE
|
| Dr.Web | Trojan.Nsanti.Packed
|
| eSafe (Alladin) | Suspicious File [100]
|
| Eset | Win32/PSW.OnLineGames.NMY
|
| FortiNet | W32/Gamania.A!tr.pws
|
| F-Prot | W32/Packed.Krap!Eldorado
|
| Kaspersky | Worm.Win32.AutoRun.ovg
|
| microsoft | worm:win32/taterf.b |
| norman | w32/vundo.fha |
| panda | W32/Wow.UY |
| rising | Packer.Win32.Mian007.a
|
| Sophos | Troj/Agent-HTK |
| Symantec | Trojan.Packed.NsAnti
|
| Trend Micro | TSPY_LINEAGE.JHA |
| vba32 | BScope.Trojan-PSW.AmGames
|
| V-Buster | Worm.AutoRun.sjy |
Vet (Computer Associates)
| Win32/Frethog.CLQ |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
Modifies memory of other processes
| Critical |
Enumerates running processes
| Medium |
Uses shared memory of other processes
| Low |
Writes executable in the windows folder
| Low |
Creates registry keys and data values to persist on OS reboot
| Informational |
Other detections that have been observed.
| FileName | McAfee Supported |
%WINDIR%\system32\ckvo0.dll
| PWS-Gamania.gen.a |
%WINDIR%\system32\ckvo.exe
| PWS-Gamania.gen.a |
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
%USERPROFILE%\local settings\temp\!itw#700.exe
The following files have been added to the system:
%WINDIR%\system32\ckvo.exe%WINDIR%\system32\ckvo0.dll
The following registry elements have been created:
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\kavsys\- errorcontrol = 1
- imagepath = \??\c:\windows\system32\drivers\klif.sys
- start = 1
- type = 1
The following registry elements have been changed:
HKEY_CURRENT_USER\Software\Microsoft\Windows\currentversion\explorer\advanced\- hidden = 2
- showsuperhidden = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\currentversion\policies\explorer\HKEY_CURRENT_USER\Software\Microsoft\Windows\currentversion\run\- kamsoft = c:\windows\system32\ckvo.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\currentversion\explorer\advanced\folder\hidden\showall\
The applications created the following network connection(s):
http- hxxp://172.16.199.200/xmfx/**********