Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | June 2007 (4.18) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Pahatia-A is a worm for the Windows platform.
When W32/Pahatia-A is installed the following files are created:
<Windows>\security\krnl32.bat
<System>\Aku Bisa Tanpamu.exe
<System>\Aku Kecewa.exe
<System>\Dibalas Dengan Dusta.exe
<System>\ISASS.exe
<System>\Kau Pikir Kaulah Segalanya.exe
<System>\LNETINFO.exe
<System>\mr.abram's.exe
<System>\Sejauh Mungkin.exe
<System>\Tak Seperti Dulu.exe
<System>\Viva Elektro.exe
<System>\Patah_0150.exe
\Documents and Settings\Administrator\My Documents\My Music\My Music.exe
\Documents and Settings\Administrator\My Documents\My Pictures\My Pictures.exe
<Desktop>\My Documents.exe
<Start Menu\Programs>\My Documents.exe
<Startup>\system startup.pif
<Program Files>\Microsoft Office\Temp.exe
<Windows>\hkcmd.exe
<Windows>\system.exe
<Windows>\Help\user logon.exe
W32/Pahatia-A sets the following registry entries:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Patah Hati
<path to worm executable>
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
user logon
<path to worm executable>
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HotKeysCmds
<path to worm executable>
The following registry entries are set, disabling the registry editor (regedit), the Windows task manager (taskmgr) and the command prompt:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableCMD
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
Registry entries are set as follows:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoRun
1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe "<Program Files>\Microsoft Office\Temp.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
RegisteredOrganization
mr.abram's
W32/Pahatia-A attempts to periodically copy itself to removable drives, including floppy drives and USB keys as:
Aku Bisa Tanpamu.exe
Aku Kecewa.exe
Dibalas Dengan Dusta.exe
ISASS.exe
Kau Pikir Kaulah Segalanya.exe
LNETINFO.exe
mr.abram's.exe
Sejauh Mungkin.exe
Tak Seperti Dulu.exe
Viva Elektro.exe
Patah_0150.exe
The worm may attempt to disable some of the following processes:
Explorer.exe
msconfig.exe
regedit.exe
taskmgr.exe
cmd.exe
ntvdm.exe
setup.exe
x-raypc.exe
rx box.exe
processxp.exe
hijackthis.exe
sysmech6.exe
integrator.exe
rstrui.exe
mmc.exe
winamp.exe
