Sophos

W32/Brontok-DN

Aliases
  • Worm.Win32.VB.gj
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 29 May 2007 20:05:35 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Brontok-DN is a worm for the Windows platform.

W32/Brontok-DN attempts to spread to removable drives by copying itself to those drives and creating the file autorun.inf on them. The file autorun.inf is also detected as W32/Brontok-DN.

When first run W32/Brontok-DN copies itself to:

<Root>\Documents.exe
<System>\shell.exe
<Windows>\winxp.exe
<Root>\winxp.exe

and creates the following files:

<Root>\Win Firewall.txt - non-malicious
<Root>\autorun.inf - detected as W32/Brontok-DN
<Windows>\Autorun.inf - detected as W32/Brontok-DN

The following registry entry is created to run winxp.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
winxp
<Windows>\winxp.exe

The following registry entries are changed to run shell.exe and winxp.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe "<System>\shell.exe"

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<Windows>\winxp.exe

The following registry entries are set or modified, so that shell.exe is run when files with extensions of BAT, COM, EXE and PIF are opened/launched:

HKCR\lnkfile\shell\open\command
(default)
<System>\shell.exe" "%1" %*

HKCR\batfile\shell\open\command
(default)
<System>\shell.exe" "%1" %*

HKCR\comfile\shell\open\command
(default)
<System>\shell.exe" "%1" %*

HKCR\exefile\shell\open\command
(default)
<System>\shell.exe" "%1" %*

HKCR\piffile\shell\open\command
(default)
<System>\shell.exe" "%1" %*

Registry entries are set as follows:

HKCR\exefile
(default)
File Folder

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoClose
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Nofolderoptions
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableCMD
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
NoDispCPL
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp
Disable
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoFolderOptions
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableRegistryTools
1

HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableConfig
1

HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableSR
1

HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer
LimitSystemRestoreCheckpointing
1

HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer
DisableMSI
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
0

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
AlternateShell
<Windows>\winxp.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer