Submission Summary:

What's been foundSeverity Level
Creates desktop.ini system file in the fake Recycle Bin folder in order to register it in Windows as a valid Recycle Bin.
Creates an executable file in the fake Recycle Bin folder with the purpose of concealing its presence in the system.
Creates fake Recycle Bin folder.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Worm.Autorun.DHA Worm.AutoRun.DHA is a network-aware worm that attempts to replicate across the existing network(s).

Threat CategoryDescription
A network-aware worm that attempts to replicate across the existing network(s)

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 c:\RECYCLER\S-51-9-25-3434476501-1644491961-601003312-1214\Desktop.ini 63 bytes MD5: 0xE783BDD20A976EAEAAE1FF4624487420
SHA-1: 0xC2A44FAB9DF00B3E11582546B16612333C2F9286
(not available)
2 c:\RECYCLER\S-51-9-25-3434476501-1644491961-601003312-1214\hjec.exe
%Windir%\crypted.exe
14,336 bytes MD5: 0x18CBB9C2563B850D33417EFD8ECF49F1
SHA-1: 0x32945A8366E7D6066B85ECB5DBB0A0B13F6B0E35
Worm.Win32.AutoRun.gmf [Kaspersky Lab]
W32/Autoham-Fam [Sophos]
Worm:Win32/Hamweq.A [Microsoft]
Worm.Win32.Hamweq [Ikarus]
Win-Trojan/Agent.13824.FE [AhnLab]
3 [file and pathname of the sample #1] 29,796 bytes MD5: 0xA960B54E7FF0C07D560493EAF5897CC0
SHA-1: 0xE1FFFDA7445F1D0F5AD738C2B8AB31A0379AF78B
Mal/Generic-A [Sophos]
VirTool.Win32.VBInject [Ikarus]
packed with PE_Patch.UPX [Kaspersky Lab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
crypted.exe%Windir%\crypted.exe24,576 bytes
[filename of the sample #1][file and pathname of the sample #1]20,480 bytes
hjec.exec:\recycler\s-51-9-25-3434476501-1644491961-601003312-1214\hjec.exe24,576 bytes

 

Registry Modifications

 

Other details

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2010 ThreatExpert. All rights reserved.