Summary
Technical details
File size of 8704 bytes.
Installation
Creates the following files on an infected computer:
-
Windows directory (usually, C:\Windows)%Windir%\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab
-
Windows directory (usually, C:\Windows)%Windir%\SoftwareDistribution\WebSetup\wuident.cab
-
Windows directory (usually, C:\Windows)%Windir%\SoftwareDistribution\WebSetup\wsus3setup.cab
Malicious activity
Modifies (deletes) Windows system files:
-
Windows directory (usually, C:\Windows)%Windir%\WindowsUpdate.log
-
Windows directory (usually, C:\Windows)%Windir%\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\wuredir.cab
Connects to to the following Internet addresses:
Creates unique identifiers to flag its presence in the system
- Global\WindowsUpdateTracingMutex
Uses the masks shown below to search for files on the victim machine:
- NPOJI*.dll
- NPJava*.dll
- NPJPI*.dll
Other activities
Runs the following files (commands):
- \"sc.exe\" config wuauserv start= auto
- \"sc.exe\" config BITS start= demand
- \"
Standard directory for programs installed on Windows OS (usually, C:\Program Files)%Program Files%\Internet Explorer\iexplore.exe \" http://windowsupdate.microsoft.com
Modifies the system registry keys:
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB} ]
"(default)" = "Java Plug-in 1.3.0_02"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32 ]
"(default)" = "
Standard directory for programs installed on Windows OS (usually, C:\Program Files)%Program Files%\Java\jre6\bin\jp2iexp.dll"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32 ]
"ThreadingModel" = "Apartment"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} ]
"(default)" = "Java Plug-in 1.3.0_03"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32 ]
"(default)" = "
Standard directory for programs installed on Windows OS (usually, C:\Program Files)%Program Files%\Java\jre6\bin\jp2iexp.dll"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32 ]
"ThreadingModel" = "Apartment"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} ]
"(default)" = "Java Plug-in 1.3.0_04"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32 ]
"(default)" = "
Standard directory for programs installed on Windows OS (usually, C:\Program Files)%Program Files%\Java\jre6\bin\jp2iexp.dll"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32 ]
"ThreadingModel" = "Apartment"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} ]
"(default)" = "Java Plug-in 1.3.0_05"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32 ]
"(default)" = "
Standard directory for programs installed on Windows OS (usually, C:\Program Files)%Program Files%\Java\jre6\bin\jp2iexp.dll"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32 ]
"ThreadingModel" = "Apartment"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} ]
"(default)" = "Java Plug-in 1.3.1"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32 ]
"(default)" = "
Standard directory for programs installed on Windows OS (usually, C:\Program Files)%Program Files%\Java\jre6\bin\jp2iexp.dll"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32 ]
"ThreadingModel" = "Apartment"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} ]
"(default)" = "Java Plug-in 1.3.1_01"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32 ]
"(default)" = "
Standard directory for programs installed on Windows OS (usually, C:\Program Files)%Program Files%\Java\jre6\bin\jp2iexp.dll"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32 ]
"ThreadingModel" = "Apartment"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} ]
"(default)" = "Java Plug-in 1.3.1_01"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32 ]
"(default)" = "
Standard directory for programs installed on Windows OS (usually, C:\Program Files)%Program Files%\Java\jre6\bin\jp2iexp.dll"
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32 ]
"ThreadingModel" = "Apartment"
Deletes the following system registry keys:
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB} ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32 ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32 ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32 ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32 ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32 ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32 ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32 ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\InprocServer32 ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\InprocServer32 ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\InprocServer32 ]
[
System registry hive HKEY_CURRENT_USERHKCU\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} ]