Sophos

W32/Rubble-C

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2007 (4.21)
Protection available since 28 July 2007 05:48:41 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rubble-C is a worm for the Windows platform.

The worm has the functionality to spread via removable storage devices.

When run, the worm copies itself to:

\WINDOWS.exe
<Windows>\.exe
<Windows>\ActiveX.exe
<Windows>\friska_w32.exe
<Windows>\win32.exe
<System>\csrss.exe
<System>\lsass.exe
<System>\smss.exe
<System>\svchost.exe
<System>\winlogon.exe
<System>\_default.pif
<System>\copy.pif
<System>\surif.bin

The worm creates the following files:

\baca euy.txt
<System>\Oeminfo.ini

These files can be safely removed.

The worm hides the folder <Windows> by setting the folder attribute to hidden.

The following registry entries are created to run the worm on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
 present
<Windows>\.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Raymond present
<Windows>\friska_w32.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Administrator
<System>\winlogon.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Default
<System>\_default.pif

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<Windows>\ActiveX.exe

The following registry entries are changed to run win32.exe and copy.pif on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
Debugger
<Windows>\win32.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
Debugger
<Windows>\win32.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
Debugger
<Windows>\win32.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
Debugger
<Windows>\win32.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\copy.pif

(the default value for this registry entry is "<Windows>\System32\userinit.exe,").

The following registry entry is set, disabling system restore:

HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableConfig
1

Registry entries are set as follows:

HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer
DisableMSI
1

HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer
LimitSystemRestoreCheckpointing
1

HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableSR
0

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoFind
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer