Sophos

W32/QQRob-ADN

Aliases
  • Trojan-PSW.Win32.QQPass.jh
  • Win32/PSW.QQPass.NBL
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 26 June 2007 22:52:13 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/QQRob-ADN is a worm for the Windows platform.

W32/QQRob-ADN spreads by copying itself to removable storage devices.

When first run W32/QQRob-ADN copies itself to:

<System>\drivers\conime.exe
<System>\drivers\pnvifj.exe
<System>\jusodl.exe
<System>\severe.exe

and creates the following files:

<System>\hx1.bat
<System>\jusodl.dll

The file hx1.bat is clean and can safely be deleted.

The file jusodl.dll is detected as Troj/QQRob-ACM.

W32/QQRob-ADN copies itself to removable storage devices as the hidden file oso.exe and creates a hidden autorun.inf to launch oso.exe automatically when the device is plugged in. The autorun.inf file is also detected as W32/QQRob-ADN. The worm may also copy itself to the device with non-alphanumeric filenames and with a PIF extension.

W32/QQRob-ADN attempts to block access to security-related sites by modifying the HOSTS file.

The following registry entries are created to run jusodl.exe and severe.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
pnvifj
<System>\jusodl.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
jusodl
<System>\severe.exe

The following registry entries are changed to run conime.exe and pnvifj.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EGHOST.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.kxp
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvDetect.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP.kxp
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MagicSet.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NOD32.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ras.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.EXE
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmo.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.com
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.com
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe
Debugger
<System>\drivers\pnvifj.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe <System>\drivers\conime.exe

W32/QQRob-ADN sets the following registry entries, disabling the automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\srservice
Start
4

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue
0

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer