Content

Downloader-AZN!72FEA1E9

Type
Trojan
SubType
Downloader
Discovery Date
10/27/2008
Length
38520
Minimum DAT
5415 (10/24/2008)
Updated DAT
5415 (10/24/2008)
Minimum Engine
5.3.00
Description Added
10/27/2008
Description Modified
10/27/2008 1:39 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

File PropertyProperty Value
FileName022.exe
McAfee DetectionDownloader-AZN
Length38,520 bytes
CRC72FEA1E9
MD585304BE39BFC1994A996EDCD418710AB
SHA1E2BE926B769D4CEA60E4B6FEA30AAA5CACF0ED21

Other Common Detection Aliases

Company NameDetection Name
avastWin32:Agent-SIM
AVG (GriSoft)worm/generic.ndw
AviraTR/Dropper.Gen
BitDefenderGeneric.Malware.SP!dldg.2A8E869A
Eseta variant of Win32/AutoRun.Delf.I
KasperskyWorm.Win32.AutoRun.ren
normanW32/Packed_Upack.A
SophosSus/Dropper-R
SymantecTrojan.Dropper
Trend MicroCryp_Mangled
vba32Backdoor.XiaoBird.5

Avert® Labs has observed the following system activities:

ActivityRisk Level
Enumerates open windows
Medium
Enumerates running processes
Medium
Uses shared memory of other processes
Low
Writes executable in the system folder
Low
Writes executable in the windows folder
Low
Performs a shell execute of downloaded or existing files
Informational

Other detections that have been observed.

FileNameMcAfee Supported
%WINDIR%\system\llwzjy081026.exe
Downloader-AZN
%WINDIR%\system\mvjaj32dla.dll
Downloader-AZN

System Changes

These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files

The following files have been added to the system:

  • %ALLUSERSPROFILE%\jjjydf16.ini
  • %WINDIR%\system\llwzjy081026.exe
  • %WINDIR%\system\mvjaj32dla.dll
  • The following registry elements have been created:

  • hkey_local_machine\software\microsoft\windows\currentversion\policies\explorer\run\
    • dlnajjbdfa = c:\windows\system\llwzjy081026.exe
  • The following registry elements have been changed:

  • hkey_local_machine\software\microsoft\windows\currentversion\explorer\advanced\folder\hidden\showall\
    • checkedvalue = 0
  • hkey_users\s-1-5-21-1202660629-602609370-839522115-500\software\microsoft\internet explorer\main\
    • check_associations = no
  • hkey_users\s-1-5-21-1202660629-602609370-839522115-500\software\microsoft\windows\currentversion\internet settings\
    • enableautodial = 0
  • The applications created the following network connection(s):

  • http
    • hxxp://172.16.199.200/cj
      /*********************************************************
  • Symptoms

    This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

    Method of Infection

    Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.

    Removal

    AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

    Additional Windows ME/XP removal considerations

    Variants

    Variants

      N/A

    All Information

    Overview -

    This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include e-mail, malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

    Characteristics

    Characteristics -

    File PropertyProperty Value
    FileName022.exe
    McAfee DetectionDownloader-AZN
    Length38,520 bytes
    CRC72FEA1E9
    MD585304BE39BFC1994A996EDCD418710AB
    SHA1E2BE926B769D4CEA60E4B6FEA30AAA5CACF0ED21

    Other Common Detection Aliases

    Company NameDetection Name
    avastWin32:Agent-SIM
    AVG (GriSoft)worm/generic.ndw
    AviraTR/Dropper.Gen
    BitDefenderGeneric.Malware.SP!dldg.2A8E869A
    Eseta variant of Win32/AutoRun.Delf.I
    KasperskyWorm.Win32.AutoRun.ren
    normanW32/Packed_Upack.A
    SophosSus/Dropper-R
    SymantecTrojan.Dropper
    Trend MicroCryp_Mangled
    vba32Backdoor.XiaoBird.5

    Avert® Labs has observed the following system activities:

    ActivityRisk Level
    Enumerates open windows
    Medium
    Enumerates running processes
    Medium
    Uses shared memory of other processes
    Low
    Writes executable in the system folder
    Low
    Writes executable in the windows folder
    Low
    Performs a shell execute of downloaded or existing files
    Informational

    Other detections that have been observed.

    FileNameMcAfee Supported
    %WINDIR%\system\llwzjy081026.exe
    Downloader-AZN
    %WINDIR%\system\mvjaj32dla.dll
    Downloader-AZN

    System Changes

    These are general defaults for typical path variables. (Although they may differ, these examples are common.):
    %WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
    %SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
    %ProgramFiles% = \Program Files

    The following files have been added to the system:

  • %ALLUSERSPROFILE%\jjjydf16.ini
  • %WINDIR%\system\llwzjy081026.exe
  • %WINDIR%\system\mvjaj32dla.dll
  • The following registry elements have been created:

  • hkey_local_machine\software\microsoft\windows\currentversion\policies\explorer\run\
    • dlnajjbdfa = c:\windows\system\llwzjy081026.exe
  • The following registry elements have been changed:

  • hkey_local_machine\software\microsoft\windows\currentversion\explorer\advanced\folder\hidden\showall\
    • checkedvalue = 0
  • hkey_users\s-1-5-21-1202660629-602609370-839522115-500\software\microsoft\internet explorer\main\
    • check_associations = no
  • hkey_users\s-1-5-21-1202660629-602609370-839522115-500\software\microsoft\windows\currentversion\internet settings\
    • enableautodial = 0
  • The applications created the following network connection(s):

  • http
    • hxxp://172.16.199.200/cj
      /*********************************************************
  • Symptoms

    Symptoms -

    This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

    Method of Infection

    Method of Infection -

    Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.

    Removal -

    Removal -

    AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

    Additional Windows ME/XP removal considerations

    Variants

    Variants -

      N/A