Virus: W32/Sohanad.R Date discovered: 19/07/2007 Type: Worm In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low Damage Potential: Low to medium Static file: No File size: 240.128 Bytes IVDF version: 6.39.00.168 - Thu, 19 Jul 2007 18:52 (GMT+1)
General Method of propagation: • No own spreading routine Aliases: • Symantec: W32.Svich • Mcafee: W32/YahLover.worm virus • Kaspersky: Trojan-Downloader.Win32.AutoIt.aa • F-Secure: Trojan-Downloader.Win32.AutoIt.aa • Sophos: W32/Sohana-R • Panda: W32/Sohanat.BP.worm • VirusBuster: Trojan.DL.AutoIt.DO • Eset: Win32/Sohanad.NAK worm • Bitdefender: Worm.IM.Agent.G Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads files • Drops a malicious file • Registry modification Files It copies itself to the following locations: • %SYSDIR% \SSVICHOSST.exe • %WINDIR% \SSVICHOSST.exe – %SYSDIR% \autorun.ini Further investigation pointed out that this file is malware, too. Detected as: INF/AutoRun.J It tries to download some files: – The location is the following: • http://nhatquanglan3.t35.com/**********.nql It is saved on the local hard drive under: %temporary internet files% \Content.IE5\%random character string% \setting[1].nql At the time of writing this file was not online for further investigation. – The location is the following: • http://nhatquanglan4.t35.com/**********.nql It is saved on the local hard drive under: %temporary internet files% \Content.IE5\%random character string% \setting[1].nql Registry The following registry keys are added in order to run the processes after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "Yahoo Messengger"="%SYSDIR% \SSVICHOSST.exe" – [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] • "Shell"="Explorer.exe SSVICHOSST.exe" The following registry keys are added: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ WorkgroupCrawler\Shares] • "shared"="\New Folder.exe" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] • "NofolderOptions"=dword:00000001 The following registry keys are changed: Disable Regedit and Task Manager: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] New value: • "DisableTaskMgr"=dword:00000001 • "DisableRegistryTools"=dword:00000001 – [HKLM\SYSTEM\ControlSet001\Services\Schedule] New value: • "AtTaskMaxHours"=dword:00000000 File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • UPXSee a brief description here . Description inserted by Andreas Feuerstein on Tue, 09 Sep 2008 14:24 (GMT+1) Description updated by Andreas Feuerstein on Tue, 09 Sep 2008 15:30 (GMT+1)