Submission Summary:

What's been foundSeverity Level
Compromises SafeBoot registry key(s) in an attempt to disable the Safe Mode.
Registers a 32-bit in-process server DLL.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Backdoor.LegMir.BZ Backdoor.LegMir.BZ is a backdoor Trojan horse. On execution it installs itself as a legitimate program, copies itself with various names and at various locations on the infected machine, opens a port and gives unauthorized access to attackers. It also has the ability to capture passwords and send that information to the author of this program.

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment
A virus capable to modify other files by infecting, prepending, or overwriting them them with its own body

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 c:\AUTORUN.INF 172 bytes MD5: 0x106B537598BCE8003D787F4C47E6ECB9 Trojan.Noupdate.B [Symantec]
Downloader.inf [McAfee]
2 c:\pagefile.pif
%System%\894729.log
%System%\Com\LSASS.EXE
90,632 bytes MD5: 0xF4D76131DE99DE0AC3CB624AE96C3491 Packed/FSG [PCTools]
Virus.Win32.Xorer.dc [Kaspersky Lab]
3 %System%\Com\netcfg.000
%System%\Com\netcfg.dll
16,384 bytes MD5: 0x7717B0F79DA72B7B413737F01E77D046 Virus.Win32.Xorer.cr [Kaspersky Lab]
4 %System%\Com\SMSS.EXE 20,637 bytes MD5: 0xA4089E292D473CC4BEE6499633F75AC1 Packed/FSG [PCTools]
Virus.Win32.Xorer.dc [Kaspersky Lab]
5 %System%\dnsq.dll 23,552 bytes MD5: 0x50771484E03F7F87F6DF271D92EB2CC5 (not available)
6 %System%\ntfsus.exe 35,840 bytes MD5: 0x12D935E6CCF72C1E140CB8F5FF5B315D Virus.Win32.Xorer.dc [Kaspersky Lab]
7 [file and pathname of the sample #1]
[file and pathname of the sample #1].log
304,148 bytes MD5: 0x1184EC3A1AC86D543DAA8A8A9D5A9647 Packed/FSG [PCTools]
Virus.Win32.Xorer.dc [Kaspersky Lab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
LSASS.EXE%System%\com\lsass.exe147,456 bytes
[filename of the sample #1][file and pathname of the sample #1]147,456 bytes
SMSS.EXE%System%\com\smss.exe73,728 bytes
[filename of the sample #1].log[file and pathname of the sample #1].log147,456 bytes
ntfsus.exe%System%\ntfsus.exe73,728 bytes

Module NameModule FilenameAddress Space Details
dnsq.dll%System%\dnsq.dllProcess name: explorer.exe
Process filename: %Windir%\explorer.exe
Address space: 0x19B0000 - 0x19C2000
dnsq.dll%System%\dnsq.dllProcess name: sdnsmain.exe
Process filename: %Windir%\dns\sdnsmain.exe
Address space: 0x1600000 - 0x1612000
dnsq.dll%System%\dnsq.dllProcess name: IEXPLORE.EXE
Process filename: %ProgramFiles%\internet explorer\iexplore.exe
Address space: 0x1B20000 - 0x1B32000

 

Registry Modifications

 

Other details

China

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2009 ThreatExpert. All rights reserved.