Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 14 February 2007 08:05:47 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Brontok-CR is a worm for the Windows platform that spreads via removeable storage drives. W32/Brontok-CR is a worm for the Windows platform that spreads via removeable storage drives.
When first run W32/Brontok-CR copies itself to:
<User>\My Documents\backup.exe
<Common Files>\Microsoft Shared\smss.exe
<Windows>\send.exe
<System>\backup.exe
<System>\brontok.exe
<System>\cmd.com
<System>\drivers\winlogon.exe
<System>\kangen.exe
<System>\notapad.exe
<System>\pesin.exe
<System>\riyani_jangkaru.exe
<System>\send.sys
<System>\sffc.exe
<System>\sysconfyg.exe
<System>\sysedyt.exe
<System>\systask.exe
<System>\windows.exe
<System>\www.google.com.exe
<System>\www.vaksin.com.exe
<System>\www.yahoo.com.exe
and creates the files
<System>\server.bat - this file can be safely removed
<Windows>\log.config - this file can be safely removed
W32/Brontok-CR is registered as a new system driver service named "Services" with a display name of "Services", a description of "Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start." and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\Services\
The following registry entries are set to run W32/Brontok-CR on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Display
<Root>\backup.exe
The following registry entries are also set:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
1-sukarno
<Root>\sukarno.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
2-suharto
<Root>\suharto.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
3-habibie
<Root>\habibie.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
4-gusdur
<Root>\gusdur.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
5-megawati
<Root>\megawati.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
6-susilo b
<Root>\sby.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSetFolders
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskmgr
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion
RegisteredOrganization
Bukan Brontok
Registry entries are also created under:
HKCR\.config\
HKCR\configfile\

