Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 29 May 2007 20:05:35 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Brontok-DN is a worm for the Windows platform.
W32/Brontok-DN attempts to spread to removable drives by copying itself to those drives and creating the file autorun.inf on them. The file autorun.inf is also detected as W32/Brontok-DN.
When first run W32/Brontok-DN copies itself to:
<Root>\Documents.exe
<System>\shell.exe
<Windows>\winxp.exe
<Root>\winxp.exe
and creates the following files:
<Root>\Win Firewall.txt - non-malicious
<Root>\autorun.inf - detected as W32/Brontok-DN
<Windows>\Autorun.inf - detected as W32/Brontok-DN
The following registry entry is created to run winxp.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
winxp
<Windows>\winxp.exe
The following registry entries are changed to run shell.exe and winxp.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe "<System>\shell.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<Windows>\winxp.exe
The following registry entries are set or modified, so that shell.exe is run when files with extensions of BAT, COM, EXE and PIF are opened/launched:
HKCR\lnkfile\shell\open\command
(default)
<System>\shell.exe" "%1" %*
HKCR\batfile\shell\open\command
(default)
<System>\shell.exe" "%1" %*
HKCR\comfile\shell\open\command
(default)
<System>\shell.exe" "%1" %*
HKCR\exefile\shell\open\command
(default)
<System>\shell.exe" "%1" %*
HKCR\piffile\shell\open\command
(default)
<System>\shell.exe" "%1" %*
Registry entries are set as follows:
HKCR\exefile
(default)
File Folder
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoClose
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Nofolderoptions
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableCMD
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
NoDispCPL
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp
Disable
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoFolderOptions
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableRegistryTools
1
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableConfig
1
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableSR
1
HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer
LimitSystemRestoreCheckpointing
1
HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer
DisableMSI
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
0
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
AlternateShell
<Windows>\winxp.exe
