Home→Descriptions→Trojan.Win32.Autoit.ci
| Detected | May 03 2008 12:22 GMT |
| Released | May 26 2008 08:13 GMT |
| Published | Oct 06 2009 15:47 GMT |
This Trojan installs other programs to the victim machine without the knowledge or consent of the user. It is a compiled AutoIt script. It is 617 473 bytes in size. It is packed using ASPack. The unpacked file is approximately 678 KB in size.
Once launched, the Trojan copies its body to the following files:
%System%\regsvr.exe (the file is created with the "hidden" attribute) %System%\svchost.exe (the file is created with the "hidden" attribute) %WinDir%\regsvr.exeIn order to ensure that it is launched automatically each time the system is rebooted, the Trojan add links to its copies to the following system registry keys:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "Msn Messsenger" = "%System%\regsvr.exe" [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "Shell" = "... regsvr.exe"This way the original Trojan file will be launched by the process "winlogon.exe" even if Windows boots up in safe mode.
Once launched, the Trojan performs the following actions:
87.***.14 69.***.224
%System%\<rnd>where <rnd> is a random five-digit decimal number.
%System%\<rnd>\svchost.exe(525 312 bytes; detected by Kaspersky Anti-Virus as "not-a-virus:Monitor.Win32.Ardamax.ae")
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NofolderOptions" = 0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr" = 0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools" = 1The modification of the last key disables the registry editor.
%System%\setup.ini (96 bytes)with the following content:
[Autorun] Open=regsvr.exe Shellexecute=regsvr.exe Shell\Open\command=regsvr.exe Shell=Open
/C AT /delete /yesThis cancels all scheduled tasks in Windows Task Scheduler.
/C AT 09:00 /interactive /EVERY:m,t,w,th,f,s,su %System%\svchost.exe
If your computer does not have antivirus protection and has been infected by this malicious program, follow the instructions below to delete it:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "Msn Messsenger" = "%System%\regsvr.exe"
%System%\setup.ini
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "Shell" = "... regsvr.exe" [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NofolderOptions" = 0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr" = 0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools" = 1
/C AT /delete /yes
%System%\regsvr.exe %System%\svchost.exe %WinDir%\regsvr.exe %System%\<rnd>\svchost.exe
%System%\<rnd>
This type of behaviour covers malicious programs that delete, block, modify, or copy data, disrupt computer or network performance, but which cannot be classified under any of the behaviours identified above.
This classification also covers “multipurpose” Trojan programs, i.e. those that are capable of conducting several actions at once and which demonstrate several Trojan behaviours in a single program. This means they cannot be indisputably classified as having any single behaviour.
Trojan.