Virus Characteristics
| File Property | Property Value |
| FileName | sk.exe |
| McAfee Artemis | Artemis!4894f6dd2862
|
| McAfee Detection | Generic.dx!gcq |
| Length | 207,360 bytes |
| CRC | D6CA7B79 |
| MD5 | 4894F6DD2862E118061587AE6DCCCBE1
|
| SHA1 | 66F5429F8F813C1A73A169E10249DE2E9492F8F9
|
Other Common Detection Aliases
| Company Name | Detection Name |
| Avira | Worm/Pinit.GY |
| FortiNet | W32/Bredo.C |
| Kaspersky | Worm.Win32.Pinit.gy |
| microsoft | ~VirTool:Win32/Obfuscator.HG
|
| Sophos | Mal/Bredo-C |
| Symantec | Packed.Generic.258 |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
Enumerates running processes
| Medium |
Uses shared memory of other processes
| Low |
Writes executable in the windows folder
| Low |
Other detections that have been observed.
| FileName | McAfee Supported |
%WINDIR%\system32\g42x.ge
| W32/Mariofev!enc |
%WINDIR%\system32\azton.mt
| Generic.dx!gcq |
%WINDIR%\system32\dllcache\user32.dll
| Patched User32 |
%WINDIR%\system32\few1.bbv
| W32/Mariofev!enc |
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
%USERPROFILE%\local settings\temp\sk.exe
The following files have been added to the system:
%WINDIR%\system32\azton.mt%WINDIR%\system32\dllcache\termsrv.dll%WINDIR%\system32\dllcache\user32.dll%WINDIR%\system32\fev2.sc%WINDIR%\system32\few1.bbv%WINDIR%\system32\g42x.ge%WINDIR%\system32\nvrmn.dll%WINDIR%\system32\termsrv.dll%WINDIR%\system32\user32.dll
The following registry elements have been created:
HKEY_LOCAL_MACHINE\software\1\- 31897356954c2cd3d41b221e3f24f99bba = 51464
- 31ac70412e939d72a9234cdebb1af5867b =
efipdhioiijnjpjcjmidigigimgfgkgkhkhfcojedpehjjjifpikecep
- 31c2e1e4d78e6a11b88dfa803456a1ffa5 = 0
HKEY_LOCAL_MACHINE\software\3\- 31897356954c2cd3d41b221e3f24f99bba = 51464
- 31ac70412e939d72a9234cdebb1af5867b =
nqrckqqlqdrqrirprhqoqrqdqpoinfnhmjmqrjrjlmmdmpnrrkqhnrmq
- 31c2e1e4d78e6a11b88dfa803456a1ffa5 = 0
HKEY_LOCAL_MACHINE\software\9\- 31897356954c2cd3d41b221e3f24f99bba = 51464
- 31ac70412e939d72a9234cdebb1af5867b =
kgomncpjpnogoconproiodorojqoqhqfrprgmlmlocrnrnqkldkrocodpe
- 31c2e1e4d78e6a11b88dfa803456a1ffa5 = 0
The following registry elements have been changed:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows nt\currentversion\Windows\HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\currentversion\- mid = f398b51be07b4315934c8d635a5780d4d141bb89f68e482e862d374b10e1ccc4
- tt = 1
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\terminal server\- fdenytsconnections = 0
- tsenabled = 1
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\terminal server\licensing core\- enableconcurrentsessions = 1