Sophos

W32/Pahatia-A

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2007 (4.18)
Detected by All Sophos products

Action

More Information

W32/Pahatia-A is a worm for the Windows platform.

When W32/Pahatia-A is installed the following files are created:

<Windows>\security\krnl32.bat
<System>\Aku Bisa Tanpamu.exe
<System>\Aku Kecewa.exe
<System>\Dibalas Dengan Dusta.exe
<System>\ISASS.exe
<System>\Kau Pikir Kaulah Segalanya.exe
<System>\LNETINFO.exe
<System>\mr.abram's.exe
<System>\Sejauh Mungkin.exe
<System>\Tak Seperti Dulu.exe
<System>\Viva Elektro.exe
<System>\Patah_0150.exe
\Documents and Settings\Administrator\My Documents\My Music\My Music.exe
\Documents and Settings\Administrator\My Documents\My Pictures\My Pictures.exe
<Desktop>\My Documents.exe
<Start Menu\Programs>\My Documents.exe
<Startup>\system startup.pif
<Program Files>\Microsoft Office\Temp.exe
<Windows>\hkcmd.exe
<Windows>\system.exe
<Windows>\Help\user logon.exe

W32/Pahatia-A sets the following registry entries:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Patah Hati
<path to worm executable>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
user logon
<path to worm executable>

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HotKeysCmds
<path to worm executable>

The following registry entries are set, disabling the registry editor (regedit), the Windows task manager (taskmgr) and the command prompt:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableCMD
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

Registry entries are set as follows:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoRun
1

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe "<Program Files>\Microsoft Office\Temp.exe"

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
RegisteredOrganization
mr.abram's

W32/Pahatia-A attempts to periodically copy itself to removable drives, including floppy drives and USB keys as:

Aku Bisa Tanpamu.exe
Aku Kecewa.exe
Dibalas Dengan Dusta.exe
ISASS.exe
Kau Pikir Kaulah Segalanya.exe
LNETINFO.exe
mr.abram's.exe
Sejauh Mungkin.exe
Tak Seperti Dulu.exe
Viva Elektro.exe
Patah_0150.exe

The worm may attempt to disable some of the following processes:

Explorer.exe
msconfig.exe
regedit.exe
taskmgr.exe
cmd.exe
ntvdm.exe
setup.exe
x-raypc.exe
rx box.exe
processxp.exe
hijackthis.exe
sysmech6.exe
integrator.exe
rstrui.exe
mmc.exe
winamp.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer