Submission Summary:

What's been foundSeverity Level
Threat characteristics of Vundo (aka VirtuMonde/VirtuMundo), a trojan horse that cause popups and advertises rogue antispyware programs. Vundo can be installed by visiting a Web site link contained in a spammed email. It is known to create a DLL file in the Windows system32 directory and inject it into system processes winlogon.exe and explorer.exe.
Hosts file modification that may block access to the security web sites.
Downloads/requests other files from Internet.
Registers a Winlogon notification package so that the installed module is loaded into the address space of winlogon.exe.
Registers a 32-bit in-process server DLL.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Trojan.Virtumonde Virtumonde modifies the Windows Internet connection mechanism and display various pop-up advertisements.

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\vtUlLDSi.bat 87 bytes MD5: 0x3085E917A1D8F347C3711EEB1E3216EF
SHA-1: 0x979301F413904347AA4168B72F76BFFDB9CA33F6
(not available)
2 %System%\iifGwXoP.dll 37,376 bytes MD5: 0x99889D68E7B84842C91AC05F183B65EA
SHA-1: 0x5323F59DFFFA6EB6FA7BDCCBA8FF0FBC166B942D
Packed.Generic.203 [Symantec]
Trojan:Win32/Vundo.gen!R [Microsoft]
Trojan.Vundo [Ikarus]
3 [file and pathname of the sample #1] 870,912 bytes MD5: 0x98964436699F52FF55F9FDEEDBFBB249
SHA-1: 0x8D58BB0C47EC51C9B9A82BD0386DCB909A58D765
Trojan.Win32.VB.hux [Kaspersky Lab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
uni000.exe%Temp%\IXP001.TMP\uni000.exe20,480 bytes
UNINST~3.EXE%Temp%\IXP000.TMP\UNINST~3.EXE135,168 bytes
UNINST~1.EXE%Temp%\IXP001.TMP\UNINST~1.EXE94,208 bytes
[filename of the sample #1][file and pathname of the sample #1]884,736 bytes

Module NameModule FilenameAddress Space Details
iifGwXoP.dll%System%\iifGwXoP.dllProcess name: explorer.exe
Process filename: %Windir%\explorer.exe
Address space: 0x19C0000 - 0x19DB000

 

Registry Modifications

 

Other details

URL to be downloadedFilename for the downloaded bits
http://childhe.com/pas/apstpldr.dll.html?affid=163328&uid=&guid=60CAC8EB84284D6CBD179DF959D658E8%System%\pmnoLeef.dll

 

 

Downloaded File Summary:

What's been foundSeverity Level
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 [file and pathname of the sample #1] 72,192 bytes MD5: 0x9DAD88A679C9EBD08C14FF9268B02494
SHA-1: 0xB54BAA707B274A6243F25BA930A5E0A4C34D6134
Trojan Horse [Symantec]
Trojan.Win32.Pakes.mmg [Kaspersky Lab]
Trojan:Win32/Vundo [Microsoft]
Trojan.Win32.Vundo [Ikarus]

 

Memory Modifications

Module NameModule FilenameAddress Space Details
[filename of the sample #1][file and pathname of the sample #1]Process name: [generic host process]
Process filename: [generic host process filename]
Address space: 0x10000000 - 0x1001A000

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2009 ThreatExpert. All rights reserved.