Sophos

W32/Brontok-CR

Aliases
  • Email-Worm.Win32.Brontok.ad
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2007 (4.16)
Protection available since 14 February 2007 08:05:47 (GMT)
Detected by All Sophos products

Action

More Information

W32/Brontok-CR is a worm for the Windows platform that spreads via removeable storage drives. W32/Brontok-CR is a worm for the Windows platform that spreads via removeable storage drives.

When first run W32/Brontok-CR copies itself to:

<User>\My Documents\backup.exe
<Common Files>\Microsoft Shared\smss.exe
<Windows>\send.exe
<System>\backup.exe
<System>\brontok.exe
<System>\cmd.com
<System>\drivers\winlogon.exe
<System>\kangen.exe
<System>\notapad.exe
<System>\pesin.exe
<System>\riyani_jangkaru.exe
<System>\send.sys
<System>\sffc.exe
<System>\sysconfyg.exe
<System>\sysedyt.exe
<System>\systask.exe
<System>\windows.exe
<System>\www.google.com.exe
<System>\www.vaksin.com.exe
<System>\www.yahoo.com.exe

and creates the files

<System>\server.bat - this file can be safely removed
<Windows>\log.config - this file can be safely removed

W32/Brontok-CR is registered as a new system driver service named "Services" with a display name of "Services", a description of "Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start." and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\Services\

The following registry entries are set to run W32/Brontok-CR on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Display
<Root>\backup.exe

The following registry entries are also set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
1-sukarno
<Root>\sukarno.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
2-suharto
<Root>\suharto.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
3-habibie
<Root>\habibie.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
4-gusdur
<Root>\gusdur.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
5-megawati
<Root>\megawati.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
6-susilo b
<Root>\sby.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSetFolders
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskmgr
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion
RegisteredOrganization
Bukan Brontok

Registry entries are also created under:

HKCR\.config\

HKCR\configfile\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer