Virus Characteristics
| File Property | Property Value |
| FileName | !itw#143.exe |
| McAfee Artemis | Artemis!a9f7b195fccb
|
| McAfee Detection | W32/YahLover.worm!a |
| Length | 1,032,890 bytes |
| CRC | 41752A17 |
| MD5 | A9F7B195FCCB3598BAD988F7E4AD4DBF
|
| SHA1 | 52255413C0D92CAB0C07621D6E46213B3D82B9B8
|
Other Common Detection Aliases
| Company Name | Detection Name |
| ahnlab | Win-Trojan/InfoStealer.1032890
|
| avast | AutoIt:AutoRun-B2 [Wrm]
|
| AVG (GriSoft) | Generic_c.BATG |
| Avira | DR/Autoit.aar |
| BitDefender | Trojan.Generic.IS.600318
|
| clamav | INF.Autorun-32 |
| EMSI Software | Trojan.Win32.Ircbrute!IK
|
| eSafe (Alladin) | suspicious Trojan/Worm [101]
|
| Eset | Win32/AutoRun.Autoit.BG
|
| FortiNet | W32/Sohanad.S!tr |
| F-Prot | W32/Sohanad.J |
| Kaspersky | Trojan.Win32.Midgare.ahcz
|
| microsoft | Trojan:Win32/Ircbrute.A
|
| norman | Sohanad.BRU |
| panda | W32/Autoit.HH |
| Sophos | Mal/Generic-A |
| Symantec | W32.Stiraut |
| Trend Micro | WORM_SOHANAD.FM |
| vba32 | ~Trojan.Autoit.ITN |
| V-Buster | Worm.Autoit.XS |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
Enumerates open windows
| Medium |
Program often suspends itself
| Medium |
Uses shared memory of other processes
| Low |
Writes executable in the windows folder
| Low |
Creates registry keys and data values to persist on OS reboot
| Informational |
Other detections that have been observed.
| FileName | McAfee Supported |
| %WINDIR%\system.exe | W32/YahLover.worm!a |
%WINDIR%\winlogon64.exe
| Generic.dx!evl |
| %WINDIR%\msngr.exe | Generic.dx!ob |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
%USERPROFILE%\local settings\temp\!itw#143.exe
The following files have been added to the system:
%WINDIR%\msngr.exe%WINDIR%\sliame.dll%WINDIR%\stnemmoc.ocx%WINDIR%\system.exe%WINDIR%\winlogon64.exe
The following registry elements have been changed:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\currentversion\run\- twain = c:\windows\twain.exe
- windows explorer = c:\windows\system.exe
The applications created the following network connection(s):
***********:6667 (irc)- NICK Jimmy
- NICK Jimmy
USER alshea 0 0 Administrator
http- hxxp://guardians.niceboard.net/************
- hxxp://guardians.niceboard.net/*************