Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | September 2007 (4.21) |
| Protection available since | 28 July 2007 05:48:41 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rubble-C is a worm for the Windows platform.
The worm has the functionality to spread via removable storage devices.
When run, the worm copies itself to:
\WINDOWS.exe
<Windows>\.exe
<Windows>\ActiveX.exe
<Windows>\friska_w32.exe
<Windows>\win32.exe
<System>\csrss.exe
<System>\lsass.exe
<System>\smss.exe
<System>\svchost.exe
<System>\winlogon.exe
<System>\_default.pif
<System>\copy.pif
<System>\surif.bin
The worm creates the following files:
\baca euy.txt
<System>\Oeminfo.ini
These files can be safely removed.
The worm hides the folder <Windows> by setting the folder attribute to hidden.
The following registry entries are created to run the worm on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
present
<Windows>\.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Raymond present
<Windows>\friska_w32.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Administrator
<System>\winlogon.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Default
<System>\_default.pif
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<Windows>\ActiveX.exe
The following registry entries are changed to run win32.exe and copy.pif on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
Debugger
<Windows>\win32.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
Debugger
<Windows>\win32.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
Debugger
<Windows>\win32.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
Debugger
<Windows>\win32.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\copy.pif
(the default value for this registry entry is "<Windows>\System32\userinit.exe,").
The following registry entry is set, disabling system restore:
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableConfig
1
Registry entries are set as follows:
HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer
DisableMSI
1
HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer
LimitSystemRestoreCheckpointing
1
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableSR
0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoFind
1
