Largest Directoty of Internet Security Software

Internet Security Threats

Home Software Threats Security
News
 

W32.Miprinc@mm

RISK LEVEL:2



W32.Miprinc@mm is a mass-mailing worm that spreads by copying itself to local drives, network mapped drives and removable storage devices.

Protection

  • Virus Definitions (LiveUpdate™ Daily) January 26, 2007
  • Virus Definitions (LiveUpdate™ Weekly) January 31, 2007
  • Virus Definitions (Intelligent Updater) January 26, 2007
  • Virus Definitions (LiveUpdate™ Plus) January 26, 2007

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Medium
  • Payload: Spreads by copying itself to local drives, network mapped drives and removable storage devices
  • Modifies Files: Infects .exe files it finds on all drives.
  • Compromises Security Settings: Ends security-related processes.

Distribution

  • Distribution Level: High
  • Subject of Email: Varies
  • Name of Attachment: Varies
  • Size of Attachment: Varies
  • Shared Drives: Copies itself to mapped drives.

When the worm executes, it drops the following files in the root directory of all drives:

  • Autorun.inf
  • Desktop.ini
  • Mr_CoolFace.scr - a copy of the worm

The worm then creates the Mr_CF folder in the following locations:
  • Root directory of all drives
  • %UserProfile%\Application Data
  • %UserProfile%\Local Settings\Application Data

The folder Mr_CF contains the following files:
  • Folder.htt
  • Mr_CF.exe - a copy of the worm

The worm also copies itself to the following locations:
  • %SystemRoot%\EXPLORER.EXE
  • %System%\Mr_CoolFace.scr
  • %System%\[RANDOM].exe
  • %System%\msvbvm60.dll
  • %Windir%\Negeri Serumpun Sebalai.pif.bat.com.scr.exe
  • %UserProfile%\Start Menu\Programs\Startup\winlogon.exe
  • %UserProfile%\Application Data\Mutant.exe
  • %UserProfile%\Application Data\SMA Negeri 1 Pangkalpinang.exe
  • %UserProfile%\Application Data\Sahang.exe
  • %UserProfile%\Application Data\Timah.exe
  • %UserProfile%\Application Data\explorer.exe
  • %UserProfile%\Desktop\Message For My Princess.scr
  • %UserProfile%\Local Settings\Application Data\Polymorph1.exe
  • %UserProfile%\Local Settings\Application Data\Polymorph2.exe
  • %UserProfile%\Local Settings\DNALSI_AKGNAB.exe
  • %UserProfile%\Local Settings\DNALSI_AKGNAB.exe.mutant
  • %UserProfile%\Local Settings\Mr_CF_Mutation.Excalibur
  • %UserProfile%\Local Settings\[RANDOM].exe

Next, the worm creates the following registry entries so that it runs every time Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"[RANDOM CHARACTERS]" = "[RANDOM CHARACTERS].exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[RANDOM CHARACTERS]" = "[RANDOM CHARACTERS].exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "explorer.exe "%SystemRoot%\explorer.exe""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit:" = "%System%\userinit.exe, %SystemRoot%\explorer.exe"

The worm also creates the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sol.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\calc.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmine.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mshearts.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\freecell.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spider.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANSAV.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANSAV32.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winamp.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\URemovalCRC32.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Niu.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvccf.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcod.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CClaw.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcoas.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Njeeves.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nipsvc.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcsched.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zanda.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zlh.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nip.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\"Debugger" = "[FILENAME]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe\"Debugger" = "[FILENAME]"

where [FILENAME] is one of the following:

  • "%CommonProgramFiles%\kartu.exe"
  • "%CommonProgramFiles%\reged1t.exe"
  • "%CommonProgramFiles%\tskmgr.exe"
  • "%CommonProgramFiles%\kalkulator.exe"
  • "%CommonProgramFiles%\w1nm1ne.exe"
  • "%CommonProgramFiles%\N0TEPAD.exe"
  • "%CommonProgramFiles%\msheart.exe"
  • "%CommonProgramFiles%\freecel.exe"
  • "%CommonProgramFiles%\msconfag.exe"
  • "%CommonProgramFiles%\Laba_Laba.exe"
  • "%CommonProgramFiles%\_cmd.exe"

The worm then modifies the following registry entries to disable System Restore:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\"DisableConfig" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\"DisableSR" = "1"

The worm also modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"Hidden" = "2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"HideFileExt" = "1"
HKEY_CLASSES_ROOT\exefile\"(Default)" = "JPEG Image"
HKEY_CLASSES_ROOT\scrfile\"(Default)" = "JPEG Image"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState\"FullPath" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\"UncheckedValue" = "0"
HKEY_CLASSES_ROOT\txtfile\"(Default)" = "Princess Document"
HKEY_CURRENT_USER\Control Panel\Desktop\"SCRNSAVE.EXE" = "MR_COO~1.SCR"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\"AlternateShell" = "c:\explorer.exe"

The worm infects.exe files on local drives and network drives.

Next, the worm searches for files with the following extensions:

  • .SWF
  • .swf
  • .GIF
  • .gif
  • .BMP
  • .bmp
  • .BAT
  • .bat
  • .INF
  • .inf
  • .htm
  • .Avi
  • .AVI
  • .avi
  • .3Gp
  • .3GP
  • .3gp
  • .Mpg
  • .MPG
  • .mpg
  • .MIDI
  • .Midi
  • .midi
  • .Wmv
  • .WMV
  • .wmv
  • .Wma
  • .WMA
  • .wma
  • .Mp4
  • .MP4
  • .mp4
  • .Mp3
  • .MP3
  • .mp3
  • .Mid
  • .MID
  • .mid
  • .Mov
  • .MOV
  • .mov
  • .Jpeg
  • .JPEG
  • .jpeg
  • .Jpg
  • .JPG
  • .jpg

The worm changes the attributes of the above files to hidden and system. It then drops a copy of itself as [FILE NAME].scr.

The worm disables keyboard and mouse input when it discovers an active window containing any of the following titles:
  • RUN
  • NOTEPAD
  • UNTITLED

The worm then changes the window title to the following:
  • Message For My Princess
  • Mr_CoolFace Has Come !

The worm spreads by copying itself to local drives, network mapped drives and removable storage devices.

The worm may send a copy of itself to other computers as an email attachment.
The email has the following characteristics:

Subject:
One of the following:

  • Re:
  • I don't wish to lost you again!
  • Please Come Back!
  • Rindu Yang Tak Tertahankan
  • Remember Our Past?
  • Don't Forget Me,please!
  • Shall I Be The One For You ?
  • I Miss You So Much !
  • Please Remember Me.
  • Still Remember???
  • I miss U
  • Ketika Kangen bertemu Rindu
  • Lama Tak Jumpa
  • Ketika Rindu bertemu Kangen

Message Body:
One of the following:

  • I wanna be you friend. So I give you a little present ^_^
  • Ehm,....would you like to be my friend ?
  • Please check, tell me if you like it ^_^.
  • Will I meet You my old friend...
  • I miss You, I give you a file that will remind you...
  • Dear My Sweetie..
  • Here is the file, Thank you for your friendship.
  • Please, don't forget me...Ok! Take a look at the attacment, you will remember me.
  • I am missing you, please come back...
  • I give you the proof that I miss you so much!
  • Shall I be the one for you?
  • Still remember me ???
  • Do you remember me?
  • Dear My Friend..
  • Here is the file, Thank you for your cooperative.
  • Take this, please tell me if there's an error.
  • Please check, told me if there's a mistake.
  • Sorry, I forget to send you the document.
  • I'm oversleep.
  • Finally, I found the data !, what do you think ??
  • Here, the file that you want

Attachment:
One of the following:

  • Rindu dan Kangen bersatu.txt[SEVERAL SPACE CHARACTERS]pif
  • Kangen dan Rindu bersatu.tmp[SEVERAL SPACE CHARACTERS]pif
  • SweetMemory.doc[SEVERAL SPACE CHARACTERS].pif
  • Friend Reminder.doc[SEVERAL SPACE CHARACTERS].exe
  • www.lovestory.com
  • MyMind.doc[SEVERAL SPACE CHARACTERS].pif
  • CuteGame3.0 Installer.com
  • LoveGame.bmp[SEVERAL SPACE CHARACTERS].exe
  • My_Beloved.doc[SEVERAL SPACE CHARACTERS].exe
  • Love_U_So_Much.txt[SEVERAL SPACE CHARACTERS].pif
  • Our_Memory.ppt[SEVERAL SPACE CHARACTERS].pif
  • I_Miss_U.doc[SEVERAL SPACE CHARACTERS].pif
  • Rindu.doc[SEVERAL SPACE CHARACTERS].exe
  • Kenangan Cinta.doc[SEVERAL SPACE CHARACTERS].pif
  • www.Hacking_Tool.bat
  • Namo7.0_Installer.com
  • NetMeeting.com
  • MindMap.exe
  • Mahasiswi Cantik.scr
  • Crack.exe
  • Tutorial.ppt[SEVERAL SPACE CHARACTERS].pif
  • Data.doc[SEVERAL SPACE CHARACTERS].pif
  • Keygen.exe
  • Beauty ScreenSaver.scr

The worm then ends processes that contain the following strings, some of which may be security-related:
  • 0GrtMultikiller
  • 2rellikitluM
  • AD-AWARE
  • ADNAP
  • ANVIE
  • AnVir
  • ANVIR
  • AVIRA
  • BACA BRO
  • BITDEF
  • BLACKICE
  • CabinetW
  • CASTLECOP
  • CHRIS PC
  • CILIN
  • CITSITSCANNING STATISTIC
  • CLEANER
  • COMMAND BRO
  • COMPACTBYTE
  • CONFIGURATION UTILITY
  • ConsoleW
  • COPYING..
  • CURR PROCESS
  • CurrProcess
  • CURRPROCESS
  • DELETING..
  • EARTHLINK PROTECTION
  • ERTANTO
  • explorer.exe
  • EXTENSION TEST
  • FLAMMING WALL
  • FOLDER OPTION
  • FORCE
  • FREECELL
  • F-SECURE
  • GEOBLACK
  • GRISOFT
  • HACKER
  • HEARTS
  • HIJACK
  • HtrGPANDA
  • I KNOW
  • IDI0T
  • IDIOT
  • IKNOW
  • JAMILA
  • KASPERSKY
  • LUKE FILEWALKER
  • MACHINE
  • MALWARE
  • MCAFEE
  • MEDIA PLAYER
  • MIGHTY CHICKEN
  • MIGHTYCHICKEN
  • MINESWEEPER
  • MOVING..
  • Mr_CoolFace
  • Multikiller2
  • MY DOCUMENTS
  • NORMAN
  • NORTON
  • NOTESXP
  • OPTIX PRO
  • PCMAV
  • PCSUMMARIZER
  • PINBALL
  • POP3TRAP
  • POWER TOOL
  • POWERDVD
  • POWERTOOL
  • PrcView
  • PROCESS EXPLORER
  • PROCESS INFO
  • PROCESS MANAGER
  • PROCESS MONITOR
  • PROCESS VIEWER
  • Process Viewer
  • PROCESSINFO
  • PROCESSMANAGER
  • PROCESSMONITOR
  • PROCESSVIEWER
  • PROCEXP
  • PROCEXPL
  • REALPLAYER
  • REG FIX
  • REGCURE
  • RegEdit
  • REGFIX
  • REGISTRY
  • Registry Editor
  • REMOVA
  • REMOVER
  • REMOVI
  • RESULT DETAIL
  • SEARCH RESULTS
  • SECUNIA
  • SECURITY TASK
  • SIKUP
  • SOLITAIRE
  • SOPHOS
  • SPIDER
  • SPYWARE
  • STARTUP ORGANIZER
  • SYMANTEC
  • SYSINTERNAL
  • System Configuration Utility
  • System Restore
  • SYSTEM32
  • TASK INFO
  • TASK MANAGER
  • TASKGUARDIAN
  • TASKINFO
  • TASKMANAGER
  • TASKS MANAGER
  • TForm1
  • ThunderRT
  • TmainF
  • TMainF
  • TREND
  • TROJAN
  • TShowSplash
  • TSystemCleaner
  • TWEAK
  • VAKSIN
  • VIROLOG
  • VIRUS
  • WANTI
  • Warecase
  • WASHER
  • WAV V
  • WIN TASK
  • WINDOWS FILE PROTECTION
  • WINHEX
  • WINPATROL
  • WINTASK
  • wITNA
  • wProcess Explorer
  • YOHAN
  • ZANDA
  • Zanda's little helper

Recommendations

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

  • Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.
  • If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
  • Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.
  • Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
  • Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
  • Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.
  • Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
  1. Disable System Restore (Windows Me/XP).
  2. Update the virus definitions.
  3. Run a full system scan.
  4. Delete any values added to the registry.

For specific details on each of these steps, read the following instructions.

1. To disable System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:

Note: When you are completely finished with the removal procedure and are satisfied that the threat has been removed, reenable System Restore by following the instructions in the aforementioned documents.

For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article: Antivirus Tools Cannot Clean Infected Files in the _Restore Folder (Article ID: Q263455).

2. To update the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
  • Running LiveUpdate, which is the easiest way to obtain virus definitions.
  • Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted daily. You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to Virus Definitions (Intelligent Updater).

The latest Intelligent Updater virus definitions can be obtained here: Intelligent Updater virus definitions. For detailed instructions read the document: How to update virus definition files using the Intelligent Updater.

3. To run a full system scan
  1. Start your Symantec antivirus program and make sure that it is configured to scan all the files.
  2. Run a full system scan.
  3. If any files are detected, follow the instructions displayed by your antivirus program.
Important: If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, How to start the computer in Safe Mode. Once you have restarted in Safe mode, run the scan again.


After the files are deleted, restart the computer in Normal mode and proceed with the next section.

Warning messages may be displayed when the computer is restarted, since the threat may not be fully removed at this point. You can ignore these messages and click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:

Title: [FILE PATH]
Message body: Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.

4. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.
  1. Click Start > Run.
  2. Type regedit
  3. Click OK.

    Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.
  4. Navigate to and delete the following entries:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"[RANDOM CHARACTERS]" = "[RANDOM CHARACTERS].exe"
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[RANDOM CHARACTERS]" = "[RANDOM CHARACTERS].exe"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "explorer.exe "%SystemRoot%\explorer.exe""
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit:" = "%System%\userinit.exe, %SystemRoot%\explorer.exe"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sol.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\calc.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmine.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mshearts.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\freecell.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spider.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANSAV.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANSAV32.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winamp.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\URemovalCRC32.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Niu.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvccf.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcod.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CClaw.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcoas.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Njeeves.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nipsvc.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcsched.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zanda.exe\"Debugger" = "[FILENAME]" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zlh.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nip.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\"Debugger" = "[FILENAME]"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe\"Debugger" = "[FILENAME]"

  5. Restore the following registry entries to their original values, if required:

    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\"DisableConfig" = "1"
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\"DisableSR" = "1"
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"Hidden" = "2"
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"HideFileExt" = "1"
    HKEY_CLASSES_ROOT\exefile\"(Default)" = "JPEG Image"
    HKEY_CLASSES_ROOT\scrfile\"(Default)" = "JPEG Image"
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState\"FullPath" = "1"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\"UncheckedValue" = "0"
    HKEY_CLASSES_ROOT\txtfile\"(Default)" = "Princess Document"
    HKEY_CURRENT_USER\Control Panel\Desktop\"SCRNSAVE.EXE" = "MR_COO~1.SCR"
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\"AlternateShell" = "c:\explorer.exe"

  6. Exit the Registry Editor.



Printed From:http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-012610-3225-99


Similar Virus/Threat >>


  • Window Washer
  • symantec PCanywhere 12.0
  • Kaspersky Anti-Hacker
  • iSpyNOW
  • Diet Kaza

  • Acronis Privacy Expert Suite 8.0
    (31,781KB - $29.99)
    AIM Spy Monitor 2007
    (3,145KB - $39.99)
    BlazingTools Secure Office
    (1,301KB - $54.95)
    Yahoo! Messenger Spy Monitor 2007
    (4,034KB - $39.99)
    Encrypt my Folder
    (1,530KB - $24.95)

    Cookie Cleaner   |    History Eraser   |    Popup Killer   |   Firewall   |   Antivirus   |   Security Encryption   |   UnInstaller   |   Security News
    eTrust Pestpatrol Anti-Spyware   PestPatrol 5   Ad-Aware SE Removal   Ad-Aware SE   Ad-Watch   SpyFighter Cleaner Pro   Free Adware Remover   Spy Sweeper  Webroot Spy Sweeper 
    Copyright © 2002-2007 Internet Security Software.All rights reserved.
    Directory of Internet Security Software - Cookie & Cache Cleaner, History & Evidence Eraser, Popup Killer, Firewall