Home→Descriptions→Hoax.Win32.ArchSMS.ong
| Detected | Feb 05 2011 08:56 GMT |
| Released | Feb 05 2011 13:42 GMT |
| Published | Mar 16 2011 13:44 GMT |
This malicious program demands a ransom in exchange for the content of an encrypted archive, which users believe contains a file that they need. It is a Windows application (PE EXE file) and is 1 191 936 bytes in size. It is written in C++.
To ensure that its original file is launched automatically each time the system is rebooted, the Trojan creates the following system registry key:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "winxrar" = ""<full path to original Trojan file>" autostart"
Once launched, the Trojan carries out the following actions:
[HKCR\CLSID\{7E0F3F10-7B69-8C21-EE01-70DABCF57934}
\InprocServer32]
"(Default)" = "%System%\scrrun.dll"
"ThreadingModel" = "Both"
[HKCR\CLSID\{7E0F3F10-7B69-8C21-EE01-70DABCF57934}\ProgID]
"(Default)" = "Scripting.FileSystemObject"
[HKCR\CLSID\{7E0F3F10-7B69-8C21-EE01-70DABCF57934}\TypeLib]
"(Default)" = "{420B2830-E718-11CF-893D-00A0C9054228}"
[HKCR\CLSID\{7E0F3F10-7B69-8C21-EE01-70DABCF57934}\Version]
"(Default)" = "1.0"
[HKLM\Software\Licenses]
"{I72A1C76714CAA996}" = "01 00 00 00"
[HKCU\Software\winxrar]
"exerunner" = "was"
"runcounter" =
[HKLM\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL" = "http://www.sm***xi.net" "Start Page" = "http://www.sm***xi.net" [HKCU\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL" = "http://www.sm***xi.net" "Start Page" = "http://www.sm***xi.net"
%WorkDir%\xsendexe.tmpand writes the following string into it:
est
wlnr***th4.netAt the time of writing, the server was not working, so the window was displayed with this appearance.

If your computer does not have an antivirus, and is infected by this malicious program, follow the instructions below to delete it:
%WorkDir%\xsendexe.tmp
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"winxrar" = ""<full path to original Trojan file>" autostart"
[HKCR\CLSID\{7E0F3F10-7B69-8C21-EE01-70DABCF57934}\
InprocServer32]
"(Default)" = "%System%\scrrun.dll"
"ThreadingModel" = "Both"
[HKCR\CLSID\{7E0F3F10-7B69-8C21-EE01-70DABCF57934}\ProgID]
"(Default)" = "Scripting.FileSystemObject"
[HKCR\CLSID\{7E0F3F10-7B69-8C21-EE01-70DABCF57934}\TypeLib]
"(Default)" = "{420B2830-E718-11CF-893D-00A0C9054228}"
[HKCR\CLSID\{7E0F3F10-7B69-8C21-EE01-70DABCF57934}\Version]
"(Default)" = "1.0"
[HKLM\Software\Licenses]
"{I72A1C76714CAA996}" = "01 00 00 00"
[HKCU\Software\winxrar]
"exerunner" = "was"
"runcounter" = <malware launch counter>
[HKLM\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL" "Start Page" [HKCU\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL" "Start Page"
MD5: 50886C55EFEB926FA5366AB97C8F6AFA
SHA1: 3B67AD4A1D95D8D1FFC27D3E105A36EA6CAB9C2C
Programs classified as Hoax do not directly inflict any damage on the victim computer. They do send messages saying that damage has been done or will be done, or warn the user of a threat that does not actually exist. These “bad jokes” include programs that frighten users with messages about reformatting their disk (although no formatting is actually taking place), and display messages typical of viruses, etc. depending on the program author’s “sense of humor”.